4.3
CVE-2026-14858
- EPSS 0.2%
- Veröffentlicht 12.08.2026 06:00:13
- Zuletzt bearbeitet 26.08.2026 16:30:52
- Erkennungen
WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR
Crowdfunding <= 2.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Order Data Disclosure
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.
Mögliche Gegenmaßnahme
WP Crowdfunding: Update to version 2.2.1, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerUnknown
≫
Produkt
WP Crowdfunding
Default Statusunaffected
Version
0
Version <
2.2.1
Status
affected
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WP Crowdfunding
Version
*-2.2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.097 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://wpscan.com/vulnerability/59022a2a-29b2-485a-9512-cd0a27b6492b/
https://www.wordfence.com/threat-intel/vulnerabilities/id/e21656a6-5442-4a1b-866e-eba442509896