Impact
The Give Tributes WordPress plugin contains a PHP Object Injection vulnerability in versions up to 2.3.1 that can be triggered by malicious input in the 'give_tributes_ecard_notify[recipient][personalized][]' parameter. The flaw occurs when the donation form is configured to allow multiple recipients and the optional eCard custom message field is disabled during submission. Although the plugin itself does not contain a built‑in proof‑of‑concept chain, the presence of an additional plugin or theme that provides a POP chain can transform this input into arbitrary code execution, file deletion or sensitive data exfiltration. Without such a chain the vulnerability does not result in actionable damage.
Affected Systems
All installations of the LiquidWeb Give Tributes plugin for WordPress with a version numbered 2.3.1 or earlier are affected. The vulnerability is specific to the donation form logic that processes multiple recipients when the custom message option is left disabled.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical, and the lack of a known proof‑of‑concept chain means its exploitation probability is difficult to quantify, but the EPSS score is unavailable so automated tooling cannot assess likelihood. The vulnerability is not listed in CISA’s KEV catalog, suggesting there are no known public exploits at the time of this report. An attacker who can reach the form as described and who has installed a vulnerable theme or plugin containing a POP chain would be able to gain remote code execution or other destructive capabilities. The attack vector is likely remote via the website’s front‑end, relying on untrusted user input to trigger deserialization of malicious objects.
OpenCVE Enrichment