CRITICAL
9.8 CVE-2026-19658 Published 22 Sept 2026
Give Tributes WordPress Plugin PHP Object Injection Vulnerability
Worried this affects your website?
The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 2.3.1. The flaw is caused by deserialization of untrusted input, allowing unauthenticated attackers to inject a PHP object.
No known POP chain is present in the vulnerable software itself, so the vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If such a chain is present, it may allow attackers to delete arbitrary files, retrieve sensitive data, or execute code depending on the chain.
Exploitation requires specific conditions:
- The "Allow Multiple Recipients" option must be enabled for the donation form.
- The eCard "Custom Message" option must be disabled, which is the plugin default.
Reference: CVE-2026-19658 on NVD
← Back to Security News