CVE-2024-5932 is a critical insecure deserialization vulnerability in the GiveWP donation plugin for WordPress affecting all versions up to and including 3.14.1. The flaw is caused by deserialization of untrusted user-controlled data from the give_title parameter in the give_process_donation_form() code path without sufficient validation or sanitization, enabling PHP object injection. In environments where a usable property-oriented programming chain is present, the injected object graph can be abused to reach dangerous sinks and achieve remote code execution. Reported exploitation paths also allow arbitrary file deletion. Public analysis indicates the issue is reachable through exposed donation-processing functionality and related AJAX actions that can be used to obtain required form identifiers and nonces, making the bug exploitable without authentication under common deployment conditions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides operational exploit code for CVE-2024-5932, a critical unauthenticated PHP Object Injection vulnerability in the GiveWP WordPress plugin (versions up to 3.14.1). The exploit enables unauthenticated attackers to achieve remote code execution (RCE) or arbitrary file deletion by sending crafted serialized PHP objects via the 'give_title' parameter to the vulnerable AJAX endpoint (/wp-admin/admin-ajax.php). The repository contains two main Python scripts: 'CVE-2024-5932.py' (for file deletion via TCPDF deserialization) and 'CVE-2024-5932-rce.py' (for RCE via a custom POP chain leveraging shell_exec). Both scripts automate the exploitation process, including form parameter extraction and payload delivery. The included 'PoC.php' demonstrates the PHP object chain used for RCE. The README provides detailed usage instructions, environment setup, and technical analysis of the vulnerability and exploitation techniques. The exploit is not part of a framework and is intended for educational and testing purposes.
This repository contains a Python proof-of-concept exploit for CVE-2024-5932, a remote code execution vulnerability in the GiveWP plugin for WordPress. The repository consists of two files: the main exploit script (CVE-2024-5932.py) and a README.md with usage and legal disclaimers. The exploit script automates the process of exploiting the vulnerability by interacting with the WordPress admin-ajax.php endpoint. It first discovers a donation form ID and a required nonce, then crafts a malicious payload that leverages PHP object injection to trigger a call to shell_exec, resulting in a reverse shell connection to the attacker's machine. The script uses the requests and Faker Python libraries to generate realistic form data. The exploit is a functional proof-of-concept and requires the attacker to specify their own IP and port for the reverse shell. No detection or mitigation functionality is present; the code is solely for exploitation. The endpoints used are customizable and must be set to match the target environment.
This repository contains a single Metasploit module (modules/exploits/multi/http/wp_givewp_rce.rb) that exploits unauthenticated remote code execution vulnerabilities (CVE-2024-5932 and CVE-2024-8353) in the GiveWP Donation Plugin for WordPress (up to and including version 3.16.1). The exploit leverages a PHP Object Injection flaw in the donation process, allowing arbitrary command execution via a crafted serialized payload submitted through the 'give_title' field of a donation form. The module automatically discovers available donation forms, retrieves necessary nonces, and submits the exploit payload to the vulnerable AJAX endpoint (/wp-admin/admin-ajax.php). The exploit is weaponized, supporting both Unix/Linux and Windows command shells, and is capable of delivering customizable payloads. The code is structured as a standard Metasploit module, using the HttpClient and Wordpress mixins for communication and target detection. No hardcoded IPs or domains are present; the exploit targets the victim's WordPress site directly via HTTP POST requests.
This repository provides operational exploit code for CVE-2024-5932, a critical unauthenticated PHP Object Injection vulnerability in the GiveWP WordPress plugin (versions up to 3.14.1). The exploit enables unauthenticated attackers to achieve remote code execution (RCE) or arbitrary file deletion by abusing the 'give_title' parameter in donation forms. The repository contains two main Python scripts: - CVE-2024-5932.py: Exploits the vulnerability to delete arbitrary files on the server by sending a crafted serialized PHP object (using a TCPDF gadget chain) to the vulnerable endpoint. - CVE-2024-5932-rce.py: Exploits the vulnerability to execute arbitrary system commands via a PHP object injection POP chain, also sent to the same endpoint. Both scripts automate the exploitation process by scraping the donation form for required parameters, constructing the malicious payload, and sending it to '/wp-admin/admin-ajax.php' on the target WordPress site. The PoC.php file demonstrates the PHP object chain used for RCE. The README.md provides detailed usage instructions, environment setup, and analysis of the vulnerability and exploitation techniques. The exploit is operational and can be used to test or attack vulnerable GiveWP installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in GiveWP, referenced as a Metasploit module PR.
A critical PHP object injection vulnerability in GiveWP affecting versions prior to 3.14.2.
A critical remote code execution vulnerability in the GiveWP WordPress plugin (<= 3.14.1) due to PHP Object Injection. Attackers can chain accessible AJAX endpoints to obtain necessary parameters and inject a serialized payload, leading to arbitrary code execution on the server.
A critical unauthenticated remote code execution vulnerability in the GiveWP WordPress plugin caused by improper validation and sanitization of the give_title parameter, enabling PHP object injection via deserialization and arbitrary file deletion.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.