CVE-2025-0912
CRITICALGiveWP < 3.20.0 - Unauthenticated PHP Object Injection via Donation Form card_address Parameter
Title source: llmDescription
The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.
References (6)
Core 6
Core References
Scores
CVSS v3
9.8
EPSS
0.0135
EPSS Percentile
67.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (2)
givewp/givewp
< 3.20.0
stellarwp/GiveWP – Donation Plugin and Fundraising Platform
< 3.19.4
Published
Mar 04, 2025
Tracked Since
Feb 18, 2026