External risk intelligence

Give Tributes WordPress Plugin PHP Object Injection

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-19658

The vulnerability exists in a WordPress plugin designed for public donation forms. As a web-facing plugin used for collecting donations, it is commonly deployed in internet-facing configurations to receive user traffic, making the attack surface accessible to unauthenticated remote users.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the Give Tributes WordPress plugin that could allow unauthenticated attackers to inject malicious code if specific configuration options are enabled. While the vulnerability itself requires additional conditions, such as the presence of another vulnerable plugin or theme with a POP chain, to cause significant harm like data deletion or code execution, its potential impact warrants attention.

  • Plugin flaw allows code injection if conditions met.
  • Considered if extra plugins create exploit path.
  • Verify relevance and exposure for your sites.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can inject a PHP Object into the Give Tributes WordPress plugin by sending specially crafted data. This occurs when the plugin's "Allow Multiple Recipients" option is enabled and the eCard "Custom Message" option is disabled. The vulnerability, a PHP Object Injection via deserialization, has no inherent impact unless another installed plugin or theme provides a vulnerable PHP Object chain (POP chain). If such a chain exists, an attacker could potentially delete files, steal data, or execute code.

  • No authentication required.
  • Triggered via form submission with specific options.
  • Risk depends on other installed plugins/themes.

Live Threat

Current exploitation, exposure, and threat context

When a specific configuration is met, unauthenticated attackers could inject PHP objects into the Give Tributes plugin. If another plugin or theme on the site provides a viable POP chain, this could lead to actions such as deleting files, retrieving sensitive data, or executing code. This scenario is only possible when the "Allow Multiple Recipients" option is enabled for donation forms and the eCard "Custom Message" option is disabled, which is the default setting.

  • System files and sensitive data could be at risk.
  • Injection occurs via deserialization of untrusted input.
  • Potential for arbitrary file deletion or code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects the Give Tributes plugin for WordPress. Responsibility for addressing this issue likely falls to the application owners who manage the WordPress instances, potentially in coordination with infrastructure or platform teams responsible for the underlying hosting environment and security teams overseeing network exposure. The first practical step is to inventory all WordPress sites using the Give Tributes plugin, identify which instances have the "Allow Multiple Recipients" option enabled and the eCard "Custom Message" option disabled, and assess their business criticality before planning remediation.

  • Application owners must address this.
  • Verify "Allow Multiple Recipients" is enabled.
  • Plan remediation based on POP chain risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Give Tributes WordPress plugin?

Give Tributes is a WordPress plugin used to facilitate donation processing on websites. It provides specific functionality for handling tributes, such as eCard messaging and managing multiple donation recipients, often used by non-profits or organizations to manage charitable contributions online.

What does PHP Object Injection mean in CVE-2026-19658?

This vulnerability, classified as CWE-502 (Deserialization of Untrusted Data), occurs when the plugin processes data from users without sufficient validation. It allows an attacker to insert malicious PHP objects into the application. While the plugin itself does not contain the code needed to do harm, this flaw acts as a gateway; if another installed theme or plugin contains a specific sequence of code known as a POP chain, the attacker could leverage it to execute commands or manipulate files.

How can an attacker trigger this vulnerability?

An attacker needs to interact with a donation form where the 'Allow Multiple Recipients' option is active. The vulnerability is not triggered if the 'Custom Message' option for eCards is enabled, as the plugin will reject the malicious input during validation. Furthermore, the single-recipient mode is safe because it applies strict sanitization that neutralizes the attack payload.

Why should I care about this CVE if my site is internet-facing?

According to Halo Surface Signal, this plugin is designed for public-facing donation forms, which are inherently internet-accessible. This accessibility means unauthenticated remote users can attempt to send crafted data to your site. Because the plugin is often used on public pages, the potential attack surface is broad, making it important to understand if your site's specific configuration creates a valid path for exploitation.

What should I do first if I run Give Tributes?

Begin by auditing your WordPress installations to see if the Give Tributes plugin is active. Check the plugin settings on each site to confirm whether 'Allow Multiple Recipients' is turned on and if the 'Custom Message' option is disabled. If these settings are active, prioritize these sites for updates or configuration changes while you assess the broader ecosystem of plugins installed on those specific systems.

References