4.3

CVE-2026-14858

Exploit

WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR

Crowdfunding <= 2.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Order Data Disclosure

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.
Mögliche Gegenmaßnahme
WP Crowdfunding: Update to version 2.2.1, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerUnknown
≫
Produkt WP Crowdfunding
Default Statusunaffected
Version 0
Version < 2.2.1
Status affected
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt WP Crowdfunding
Version *-2.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://wpscan.com/vulnerability/59022a2a-29b2-485a-9512-cd0a27b6492b/
https://www.wordfence.com/threat-intel/vulnerabilities/id/e21656a6-5442-4a1b-866e-eba442509896
Third Party Advisory