CVE-2026-19658 is an unauthenticated PHP object-injection vulnerability in the Give Tributes plugin for WordPress through version 2.3.1. The plugin deserializes untrusted input submitted through the eCard recipient personalization functionality, allowing an attacker to inject a PHP object. The vulnerable path is reachable only for donation forms configured to allow multiple recipients while the eCard Custom Message option is disabled. The single-recipient path sanitizes the relevant input, while enabling Custom Message causes GiveWP validation to clear serialized input and reject the donation. Give Tributes has no known usable POP chain of its own; consequential exploitation depends on a compatible POP chain in another installed plugin or theme.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file Python repository is an operational scanner and donation-submission helper for CVE-2026-19658 in the WordPress Give - Tributes add-on. The primary entry point, poc.py, uses requests to enumerate target WordPress sites, probe standard GiveWP/Give Tributes plugin paths, extract version and legacy Give form details, and crawl common donation paths. It supports single-target and threaded mass operation, optional proxying, configurable paths, form IDs, payment gateways, donor email addresses, serialized payloads, JSONL result logs, and candidate/hit lists. In exploit mode it submits a legacy Give donation with two eCard recipients and places an attacker-supplied PHP serialized object into the second recipient first_name field. This abuses unsanitized recipient data being stored in donation metadata and subsequently deserialized by affected code paths. The included default stdClass object is a harmless probe; the repository provides no POP chain or direct code-execution payload. The secondary entry point, fofa_to_list.py, normalizes FOFA CSV exports into deduplicated HTTP(S) target lists, with a default FOFA query for Give Tributes assets. README.md documents prerequisites, command-line usage, field layout, expected statuses, output artifacts, and the external-gadget-chain limitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated PHP object injection vulnerability in Give Tributes for WordPress versions through 2.3.1. Exploitation requires a specific donation-form configuration and a POP chain supplied by another installed plugin or theme; Give Tributes itself has no known POP chain.
A critical unauthenticated PHP object-injection vulnerability (CWE-502) in the Give Tributes WordPress plugin through version 2.3.1. Exploitation is network-reachable and requires the donation form's "Allow Multiple Recipients" option to be enabled and eCard "Custom Message" to remain disabled. The plugin has no known POP chain itself; meaningful impact such as arbitrary file deletion, sensitive-data disclosure, or code execution depends on a separate installed plugin or theme providing a usable POP chain.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.