Description
The GiveWP Donation Plugin and Fundraising Platform for WordPress, in all versions up to and including 3.16.1, is vulnerable to a PHP Object Injection (POI) attack that allows unauthenticated arbitrary code execution. Although a patch was introduced in version 3.14.2, it was incorrect and can be bypassed. This means the vulnerability remains exploitable in subsequent versions due to the ineffective patch.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/wp/givewp_rcemsf undefined(givewp_rce) > show actions ...actions...msf undefined(givewp_rce) > set ACTION < action-name >msf undefined(givewp_rce) > show options ...show and set options...msf undefined(givewp_rce) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub