THEMETASEC

Cybersecurity News, Aggregated

Critical vulnerability in GiveWP plugin allows remote code execution

SC Media · 1 hour ago Vuln

The vulnerability, present in GiveWP versions up to 4.16.7.1, is exploitable by chaining three issues: an unsafe PHP data unserialization helper, a donation processing flow that stores attacker-controlled serialized objects, and a gadget chain within bundled libraries that enables arbitrary system command execution.

Read full story at SC Media →