CVE-2025-0912

T

he Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.

Configurations

Configuration 1 (hide)

cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:*

History

05 Mar 2025, 18:30

Type Values Removed Values Added
First Time Givewp
Givewp givewp
References () https://github.com/impress-org/givewp/pull/7679/files - () https://github.com/impress-org/givewp/pull/7679/files - Patch
References () https://plugins.trac.wordpress.org/changeset/3234114/give/trunk/src/Donations/Properties/BillingAddress.php - () https://plugins.trac.wordpress.org/changeset/3234114/give/trunk/src/Donations/Properties/BillingAddress.php - Patch
References () https://plugins.trac.wordpress.org/changeset/3234114/give/trunk/src/Donations/Repositories/DonationRepository.php - () https://plugins.trac.wordpress.org/changeset/3234114/give/trunk/src/Donations/Repositories/DonationRepository.php - Patch
References () https://plugins.trac.wordpress.org/changeset/3234114/give/trunk/src/Donors/Repositories/DonorRepository.php - () https://plugins.trac.wordpress.org/changeset/3234114/give/trunk/src/Donors/Repositories/DonorRepository.php - Patch
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3234114%40give&new=3234114%40give&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3234114%40give&new=3234114%40give&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/8a8ae1b0-e9a0-4179-970b-dbcb0642547c?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/8a8ae1b0-e9a0-4179-970b-dbcb0642547c?source=cve - Third Party Advisory
Summary
  • (es) El complemento Donations Widget para WordPress es vulnerable a la inyección de objetos PHP en todas las versiones hasta la 3.19.4 incluida, a través de la deserialización de la entrada no confiable del formulario de donaciones mediante el parámetro 'card_address'. Esto hace posible que atacantes no autenticados inyecten un objeto PHP. La presencia adicional de una cadena POP permite a los atacantes lograr la ejecución remota de código.
CPE cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:*

04 Mar 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 04:15

Updated : 2025-03-05 18:30


NVD link : CVE-2025-0912

Mitre link : CVE-2025-0912

CVE.ORG link : CVE-2025-0912


JSON object : View

Products Affected
CWE
CWE-502

Deserialization of Untrusted Data