CVE-2026-19658 — Give Tributes ≤ 2.3.1 Unauthenticated PHP Object Injection
Unauthenticated PHP object injection in **Give Tributes** (≤ 2.3.1) via unsanitized **eCard multi-recipient** POST data stored on donations (unsafe deserialization on read).
Description
Overview
CVE-2026-19658 affects the WordPress Give Tributes add-on (≤ 2.3.1) used with GiveWP-style fundraising. eCard multi-recipient fields accept attacker-controlled serialized data that may be processed unsafely later, leading to PHP object injection.
Impact
Object injection in WordPress often escalates to remote code execution via known gadget chains present in core or plugins.
Remediation
Patch or remove Give Tributes until a fixed release is installed. Review donation records for suspicious eCard payloads if you suspect compromise.
Legal and ethical use
Use bundled tools only on WordPress sites you own or have written authorization to test. Unauthorized scanning or exploitation is illegal in most jurisdictions.
References
- Look up the CVE ID on NVD and the CVE Program for official records.
- Apply vendor/plugin updates from the official repository or vendor advisory before relying on any PoC.