CVE-2025-22777
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 13, 2025
CWE ID 502
Summary
CVE-2025-22777 is a Deserialization of Untrusted Data vulnerability affecting GiveWP, a popular WordPress plugin. The issue permits Object Injection, enabling unauthorized attackers to execute arbitrary code on vulnerable installations. This vulnerability poses a serious security risk and affects GiveWP versions from n/a through 3.19.3. It is crucial for users to update their plugin to address this vulnerability as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.