POCBIT

CVE-2026-19658 — Give Tributes ≤ 2.3.1 Unauthenticated PHP Object Injection

Unauthenticated PHP object injection in **Give Tributes** (≤ 2.3.1) via unsanitized **eCard multi-recipient** POST data stored on donations (unsafe deserialization on read).

#wordpress#give-tributes#deserialization#unauthenticated

CVE:

CVE-2026-19658

Date:

2026-09-25

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-19658 affects the WordPress Give Tributes add-on (≤ 2.3.1) used with GiveWP-style fundraising. eCard multi-recipient fields accept attacker-controlled serialized data that may be processed unsafely later, leading to PHP object injection.

Impact

Object injection in WordPress often escalates to remote code execution via known gadget chains present in core or plugins.

Remediation

Patch or remove Give Tributes until a fixed release is installed. Review donation records for suspicious eCard payloads if you suspect compromise.

Legal and ethical use

Use bundled tools only on WordPress sites you own or have written authorization to test. Unauthorized scanning or exploitation is illegal in most jurisdictions.

References

  • Look up the CVE ID on NVD and the CVE Program for official records.
  • Apply vendor/plugin updates from the official repository or vendor advisory before relying on any PoC.