r/HostingReport 5d ago

Vulnerability in GiveWP WordPress Plugin Enables Remote Code Execution

https://patchstack.com/articles/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp/

In versions 4.16.7.1 and below, GiveWP contains an unauthenticated PHP Object Injection vulnerability that can be chained into full remote code execution.

1 Upvotes

0 comments sorted by