{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/givewp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:givewp:give_tributes:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-19658"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Give - Tributes (\u003c= 2.3.1)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","deserialization","rce","vulnerability"],"_cs_type":"advisory","_cs_vendors":["GiveWP"],"content_html":"\u003cp\u003eThe Give - Tributes WordPress plugin, an add-on for the GiveWP core, contains a critical vulnerability tracked as CVE-2026-19658. The issue stems from the improper handling of serialized donation meta data. When the 'Allow Multiple Recipients' feature is enabled for eCards and the 'eCard custom message' feature is disabled, the plugin stores raw \u003ccode\u003e$_POST\u003c/code\u003e data directly into the database. Specifically, the \u003ccode\u003einsert_tribute_data()\u003c/code\u003e function processes unsanitized recipient fields such as \u003ccode\u003efirst_name\u003c/code\u003e and \u003ccode\u003elast_name\u003c/code\u003e without adequate validation. An unauthenticated attacker can supply a malicious PHP serialized object within these fields during the donation process. While the plugin itself does not contain a PHP Object Injection (POI) gadget chain, the injected object is deserialized when administrative functions, such as eCard previews or resending donation receipts, are executed. If other installed plugins or the active theme contain suitable gadgets, this can be escalated to remote code execution (RCE). The vulnerability was fixed in version 2.3.1.1.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress target with the GiveWP core and the Give - Tributes plugin (version \u0026lt;= 2.3.1) installed.\u003c/li\u003e\n\u003cli\u003eAttacker verifies that the target has a legacy GiveWP donation form (v2) enabled with 'Allow Multiple Recipients' configured.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a donation request, providing a crafted serialized PHP object within the second recipient's \u003ccode\u003efirst_name\u003c/code\u003e parameter of the \u003ccode\u003egive_tributes_ecard_notify\u003c/code\u003e array.\u003c/li\u003e\n\u003cli\u003eThe plugin receives the POST request and saves the unsanitized serialized object into the donation metadata via the vulnerable \u003ccode\u003einsert_tribute_data()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe attacker completes or triggers the donation processing to finalize the storage of the malicious payload.\u003c/li\u003e\n\u003cli\u003eAn administrator accesses the donation management dashboard to preview or resend a tribute receipt.\u003c/li\u003e\n\u003cli\u003eThe application retrieves the tainted metadata and calls a deserialization function on the payload.\u003c/li\u003e\n\u003cli\u003eIf an appropriate gadget chain exists within the WordPress environment, the attacker achieves arbitrary code execution within the context of the web server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution in the context of the web server, contingent on the presence of a compatible gadget chain within the victim's WordPress environment. This could lead to full site compromise, exfiltration of sensitive donor information, or lateral movement within the hosting environment. The vulnerability is rated at 9.8 (Critical) on the CVSS 3.1 scale due to the lack of required authentication or user interaction.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT operations teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the 'Give - Tributes' WordPress plugin to version 2.3.1.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, disable the 'Allow Multiple Recipients' feature in the plugin settings.\u003c/li\u003e\n\u003cli\u003eAudit all installed plugins and themes for known POP chain gadgets to reduce the attack surface.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to inspect \u003ccode\u003egive_tributes_ecard_notify\u003c/code\u003e POST parameters for serialized object patterns (e.g., \u003ccode\u003eO:\\d+:\u0026quot;\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eMonitor server access logs for anomalous POST requests directed at donation forms containing serialized data signatures.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T07:38:08Z","date_published":"2026-09-22T07:38:08Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-19658/","summary":"An unauthenticated PHP object injection vulnerability in the Give - Tributes plugin (\u003c= 2.3.1) allows attackers to inject serialized objects during the donation process, potentially leading to RCE if chained with existing application gadgets.","title":"Unauthenticated PHP Object Injection in Give - Tributes WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-19658/"}],"language":"en","title":"CraftedSignal Threat Feed - GiveWP","version":"https://jsonfeed.org/version/1.1"}