Impact
The vulnerability is a Deserialization of Untrusted Data flaw that allows an attacker to inject Remote Code Execution. This weakness is classified as CWE-502, and if exploited, an adversary could execute arbitrary code on the WordPress site, potentially compromising confidentiality, integrity, and availability of the entire application and its underlying server.
Affected Systems
The affected products are the WordPress GiveWP plugin, produced by Liquid Web and StellarWP, in all versions up to and including 4.16.7.1. No other versions are listed as affected in the current data.
Risk and Exploitability
The CVSS score of 10 indicates the highest severity level. The EPSS score is 2%, indicating a low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector may be unauthenticated if an attacker can supply a crafted serialized payload in a request, but confirmed prerequisites are not detailed in the available data. The overall assessment remains high risk due to the potential for full code execution on the host.
OpenCVE Enrichment