Search
Search Results (6 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75930 | 2 Roxnor, Wordpress | 2 Fundengine – Donation And Crowdfunding Platform, Wordpress | 2026-08-28 | 4.3 Medium |
| The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary posts and pages — overwriting title and content, and seizing ownership by supplying an attacker-controlled post_author integer that bypasses wp_kses_post sanitization. The wp_rest nonce required by the handler is trivially obtainable by any logged-in user via /wp-admin/admin-ajax.php?action=rest-nonce and therefore does not constitute an authorization barrier. | ||||
| CVE-2026-76063 | 2 Roxnor, Wordpress | 2 Fundengine – Donation And Crowdfunding Platform, Wordpress | 2026-08-28 | 6.4 Medium |
| The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The REST endpoint used to submit the video URL has its permission_callback set to __return_true, meaning any authenticated user — including those with Subscriber-level access — can reach the vulnerable code path. | ||||
| CVE-2026-73993 | 2 Roxnor, Wordpress | 2 Fundengine, Wordpress | 2026-08-20 | 9.8 Critical |
| Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | ||||
| CVE-2026-32470 | 2 Roxnor, Wordpress | 2 Fundengine, Wordpress | 2026-08-18 | 9.8 Critical |
| Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | ||||
| CVE-2026-59560 | 2 Roxnor, Wordpress | 2 Fundengine, Wordpress | 2026-07-27 | 6.5 Medium |
| Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | ||||
| CVE-2026-57406 | 2 Roxnor, Wordpress | 2 Fundengine, Wordpress | 2026-07-13 | 6.5 Medium |
| Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6. | ||||
Page 1 of 1.