A maximum-severity security flaw has been disclosed in the WordPress GiveWP donation and fundraising plugin that exposes more than 100,000 websites to remote code execution attacks.
The flaw, tracked as CVE-2024-5932 (CVSS score: 10.0), impacts all versions of the plugin prior to version 3.14.2, which was released on August 7, 2024. A security researcher, who goes by the online alias villu164, has been credited with discovering and reporting the issue.
The plugin is ”vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the ’give_title’ parameter,” Wordfence said in a report this week.
Från AI till elbilar – trenderna som tvekar, vänder och växer
Teknik, ekonomi och kultur rör sig snabbt, men inte alltid framåt. Just nu syns flera tydliga förskjutningar där optimism möter oro och innovation landar i vardagen. Tillsammans tecknar de en bild av vart världen lutar. Uppåt – Energisnål intelligens Efter…
