CVE-2025-0912: GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection
The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'cardaddress' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0912?
CVE-2025-0912 is considered a critical vulnerability due to its ability to allow unauthenticated attackers to exploit PHP Object Injection.
How do I fix CVE-2025-0912?
To fix CVE-2025-0912, update the Donations Widget plugin to version 3.19.5 or later.
Which versions of the Donations Widget are affected by CVE-2025-0912?
All versions of the Donations Widget up to and including 3.19.4 are affected by CVE-2025-0912.
What is the impact of CVE-2025-0912 on my WordPress site?
CVE-2025-0912 can lead to remote code execution and potentially allow attackers to take control of your WordPress site.
Is CVE-2025-0912 specific to certain environments?
CVE-2025-0912 affects any WordPress environment using the vulnerable version of the Donations Widget plugin.