CVE-2025-22777

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 13, 2025
CWE ID 502

Summary

CVE-2025-22777 is a Deserialization of Untrusted Data vulnerability affecting GiveWP, a popular WordPress plugin. The issue permits Object Injection, enabling unauthorized attackers to execute arbitrary code on vulnerable installations. This vulnerability poses a serious security risk and affects GiveWP versions from n/a through 3.19.3. It is crucial for users to update their plugin to address this vulnerability as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share