CVE-2024-9634

Published Oct 16, 2024

Last updated a month ago

Insights

Analysis from the Intruder Security Team
Published Oct 16, 2024

The original fix which the developers implemented for CVE-2024-5932 was insufficient and did not cover all form fields such as "Company Name" which is used when a donation is made on behalf of a company.

The previous fix has now been extended to cover all fields that are submitted by a donations form.

Overview

Description
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input from the give_company_name parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.
Source
security@wordfence.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-502

Social media

Hype score
Not currently trending
  1. CVE-2024-9634 (CVSS:9.8, CRITICAL) is Awaiting Analysis. The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ..https://t.co/1nkAuwrSgu #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    21 Oct 2024

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 ¡ALERTA DE SEGURIDAD! 🚨 Se ha identificado una vulnerabilidad crítica (CVE-2024-9634) en el plugin de WordPress GiveWP – Donation Plugin and Fundraising Platform. Este fallo afecta a todas las versiones hasta la 3.16.3 y permite la inyección de objetos PHP por atacantes no… h

    @antu_tech

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. [CVE-2024-9634: CRITICAL] WordPress GiveWP plugin up to version 3.16.3 has a PHP Object Injection vulnerability, allowing attackers to inject code and potentially execute remote attacks. #cybersecurity#cybersecurity,#vulnerability https://t.co/KTTjEywQtI https://t.co/QGqJU30Nql

    @CveFindCom

    44 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  4. ⚠️⚠️ CVE-2024-9634 (CVSS 9.8) PHP Object Injection vulnerability in wordpress GiveWP could allow unauthenticated attackers to execute arbitrary code on vulnerable websites. 🎯44k+ Results are found on the https://t.co/pb16tGYaKe nearly year. FOFA Link🔗:https://t.co/w3TnQ39qEi…

    @fofabot

    1994 Impressions

    9 Retweets

    38 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-9634 (CVSS 9.8): Critical GiveWP Flaw Exposes 100,000+ WordPress Sites to RCE https://t.co/QCpdV1pgHs

    @Dinosn

    1791 Impressions

    4 Retweets

    6 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. CVE-2024-9634: RCE in GiveWP WordPress Plugin, 9.8 rating 🔥 Another one critical vuln in GiveWP. This time, attackers can inject PHP code using one parameter. Search at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/6mtSjUbyx6 #cybersecurity #vulnerability_map #givewp https:/

    @Netlas_io

    828 Impressions

    3 Retweets

    16 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨🚨CVE-2024-9634 (CVSS: 9.8) : Critical RCE Vulnerability in GiveWP WordPress Plugin ⚠️The flaw, a PHP Object Injection vulnerability, could allow unauthenticated attackers to execute arbitrary code on vulnerable websites, potentially compromising sensitive donor data and taking

    @zoomeye_team

    394 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2024-9634 alert 🚨 WORDPRESS : PHP Object Injection vulnerability in GiveWP plugin leading to RCE The vulnerability is actively exploited in the wild and has been integrated into Patrowl. Our customers assets are protected. 🦉 #CyberSecurity #InfoSec #WordPress https://t.

    @Patrowl_io

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes