What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
CVE-2024-5932 was a critical vulnerability in the GiveWP donation plugin—not in WordPress core. It affected GiveWP versions through 3.14.1 and was fixed in 3.14.2. Wordfence reported that GiveWP had more than 100,000 active installations, but that figure describes the plugin’s footprint; it does not mean 100,000 sites were compromised. The reviewed advisories do not establish a confirmed number of successful attacks.
What was the GiveWP vulnerability?
Wordfence reported an unauthenticated PHP Object Injection flaw in GiveWP, a WordPress plugin used for donations and fundraising. The vulnerable code deserialized untrusted input associated with the give_title parameter. Because the plugin also had a usable Property Oriented Programming (POP) chain, an attacker could potentially exploit the flaw to execute code remotely or delete arbitrary files. Wordfence rated CVE-2024-5932 CVSS 10.0, Critical. Read Wordfence’s advisory; Cal-CSIC’s advisory also describes the issue.
“Unauthenticated” means the reported vulnerability did not require an attacker to sign in first. The risk concerned the GiveWP plugin code; it was not a flaw in WordPress core itself.
Did 100,000 WordPress sites get hacked?
No confirmed compromise count is established by the reviewed sources. Wordfence reported more than 100,000 active GiveWP installations. That is an installation-footprint figure—not a count of sites that were vulnerable at a particular time, exposed to an attack, or successfully compromised.
#1 Best Overall
SecurityWeek reported on August 20, 2024, that tens of thousands of installations might still be unpatched at that time. That was a contemporaneous estimate, not a current vulnerability or compromise count. Read SecurityWeek’s report.
Which GiveWP versions were affected, and what fixed the flaw?
Wordfence lists all GiveWP versions through and including 3.14.1 as affected and 3.14.2 as fully patched. Cal-CSIC’s August 20, 2024 advisory likewise recommended upgrading to 3.14.2 or newer. Version 3.14.2 is the historical minimum fix identified in those advisories; administrators should install the latest compatible fixed release available for their site rather than stopping at that old minimum.
Rank #2
How to check and update GiveWP
- Check whether GiveWP is installed. In your WordPress dashboard, go to Plugins > Installed Plugins and find GiveWP. If it is not installed, this specific plugin vulnerability does not apply to your site.
- Check the installed version. If it is 3.14.1 or earlier, it falls within the affected range listed by Wordfence. If it is 3.14.2 or later, it is beyond the historical affected range, but still check for and install the latest compatible release.
- Update the plugin. Use the update option shown for GiveWP on the Installed Plugins page, or follow the update method provided by your site host. If no update is offered, confirm that your site can reach the appropriate plugin update source and consult GiveWP’s support or your host before assuming the installation is fixed.
- Verify the result. Return to the plugin list and confirm the installed version is the current compatible fixed release. If the update fails, do not treat the attempt as remediation: resolve the update issue with your host or GiveWP support.
Cal-CSIC’s advisory dated August 20, 2024, says: “The Cal-CSIC recommends immediately upgrading to GiveWP version 3.14.2 or newer.” View the advisory.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Does a firewall fix it?
Wordfence said its firewall included PHP Object Injection protection for this vulnerability, including for users of its free plugin. That can provide an additional defense layer, but firewall coverage is not the remediation identified in the advisories. Update GiveWP to a fixed release; do not rely on a firewall as a substitute for patching.
Quick Recap
Best Value
Rank #4
How the vulnerability was disclosed
- May 26, 2024: Wordfence received the vulnerability report.
- June 10, 2024: Wordfence said it validated the report and confirmed the proof of concept.
- June 13, 2024: Wordfence said it contacted the StellarWP team.
- July 6, 2024: Wordfence escalated the issue to the WordPress.org Security Team.
- August 7, 2024: GiveWP 3.14.2, described as fully patched, was released.
- August 19, 2024: Wordfence published its disclosure; SecurityWeek published its report the following day.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

