CVE-2025-22777
CRITICALGivewp < 3.19.4 - Insecure Deserialization
Title source: ruleDescription
Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a through <= 3.19.3.
Exploits (2)
nomisec
WORKING POC
by SevDMG · poc
https://github.com/SevDMG/CVE-2025-22777-GiveWP-Plugin-PHP-Object-Injection-Point-PoC-
References (3)
Scores
CVSS v3
9.8
EPSS
0.0055
EPSS Percentile
68.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-502
Status
published
Products (2)
givewp/givewp
< 3.19.4
StellarWP/GiveWP
< 3.19.3
Published
Jan 13, 2025
Tracked Since
Feb 18, 2026