CVE-2025-22777: WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerability
Published Jan 13, 2025
·Updated
Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a through <= 3.19.3.
Affected Software
3 affected components
GiveWP GiveWP<=3.19.3
WordPress GiveWP plugin<=3.19.3
GiveWP GiveWP WordPress<3.19.4
Remediation
Information
Update the WordPress GiveWP wordpress plugin to the latest available version (at least 3.19.4).
Event History
Jan 13, 2025
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22777?
CVE-2025-22777 has a critical severity rating due to its potential for remote code execution via object injection.
2
How do I fix CVE-2025-22777?
To fix CVE-2025-22777, update the GiveWP plugin to version 3.19.4 or higher immediately.
3
What versions are affected by CVE-2025-22777?
CVE-2025-22777 affects GiveWP versions up to and including 3.19.3.
4
What type of vulnerability is CVE-2025-22777?
CVE-2025-22777 is categorized as a deserialization of untrusted data vulnerability.
5
What should users do if they cannot update due to compatibility issues related to CVE-2025-22777?
If immediate updates are not possible due to compatibility issues, users should implement security measures to limit access to the affected plugin until an update can be performed.