{"id":"CVE-2026-19658","published":"2026-09-22T05:16:55.167","lastModified":"2026-09-22T05:16:55.167","description":"The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. This vulnerability is only reachable when the \"Allow Multiple Recipients\" option is enabled for the donation form, as the single-recipient code path applies sanitize_textarea_field() which would neutralize the payload. Exploitation additionally requires the eCard \"Custom Message\" option to be disabled, which is the plugin default: when it is enabled the personalized message becomes a required field and GiveWP's give_clean() blanks serialized input during validation, causing the donation to be rejected before it is stored.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-502"],"vendors":[],"products":[],"references":[{"url":"https://www.liquidweb.com/software/give/","tags":[]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0cdd5562-8755-4ca3-9c16-a5b364f8408b?source=cve","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection due to deserialization of untrusted input, allowing attackers to inject a PHP object and potentially execute arbitrary code if certain conditions are met.","exploitability":"Exploitation requires enabling specific options in the donation form and having another plugin or theme with a PHP Object Persistence (POP) chain installed. These preconditions make it less likely but still possible for attackers to exploit this vulnerability.","blast_radius":"If exploited, the impact could be significant, including deletion of files, retrieval of sensitive data, or execution of arbitrary code, depending on the presence and configuration of additional vulnerable plugins or themes.","remediation":"Disable the 'Allow Multiple Recipients' option for donation forms and ensure no other plugins or themes are present that contain a PHP Object Persistence (POP) chain.","tags":["rce","web","php-object-injection","wordpress"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:02:48.404Z"}}