CVE-2024-30229: WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerability
Published Mar 28, 2024
·Updated
Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.4.2.
Affected Software
3 affected components
GiveWP GiveWP<=3.4.2
WordPress Give plugin<=3.4.2
GiveWP GiveWP WordPress<3.5.0
Remediation
Information
Update to 3.5.0 or a higher version.
Event History
Mar 28, 2024
CVE Published
via MITRE·04:51 AM
Data Sourced
via MITRE·04:51 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Jul 12, 58279
Event
via MITRE·12:42 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-30229?
CVE-2024-30229 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-30229?
To mitigate CVE-2024-30229, you should upgrade GiveWP to version 3.4.3 or later immediately.
3
What specific versions of GiveWP are affected by CVE-2024-30229?
CVE-2024-30229 affects GiveWP versions from n/a through 3.4.2.
4
What type of vulnerability is CVE-2024-30229?
CVE-2024-30229 is a deserialization of untrusted data vulnerability.
5
Is the WordPress Give plugin vulnerable to CVE-2024-30229?
Yes, the WordPress Give plugin is vulnerable to CVE-2024-30229 in versions from n/a through 3.4.2.