CVE-2023-32513: WordPress GiveWP Plugin <= 2.25.3 is vulnerable to PHP Object Injection
Published Dec 28, 2023
·Updated
Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3.
Affected Software
1 affected component
GiveWP GiveWP WordPress<=2.25.3
Remediation
Information
Update to 2.26.0 or a higher version.
Event History
Dec 28, 2023
CVE Published
via MITRE·10:46 AM
Data Sourced
via MITRE·10:46 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-32513?
CVE-2023-32513 is classified as a critical vulnerability due to the potential for remote code execution through deserialization of untrusted data.
2
How do I fix CVE-2023-32513?
To fix CVE-2023-32513, update the GiveWP – Donation Plugin to version 2.25.4 or later.
3
What versions are affected by CVE-2023-32513?
CVE-2023-32513 affects all versions of GiveWP from n/a through 2.25.3.
4
What is the impact of CVE-2023-32513 on my website?
The impact of CVE-2023-32513 on your website can include unauthorized access, data leakage, and potential server compromise.
5
Is CVE-2023-32513 a common vulnerability?
CVE-2023-32513 is specific to the GiveWP – Donation Plugin and is not widely prevalent across other systems.