CVE-2026-19945
- EPSS 0.23%
- Veröffentlicht 09.09.2026 04:28:34
- Zuletzt bearbeitet 09.09.2026 15:33:34
The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for au...
CVE-2026-19944
- EPSS 0.27%
- Veröffentlicht 09.09.2026 03:28:48
- Zuletzt bearbeitet 09.09.2026 15:33:34
The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...
CVE-2026-73189
- EPSS 0.33%
- Veröffentlicht 18.08.2026 14:00:03
- Zuletzt bearbeitet 25.08.2026 16:17:26
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-14858
CVE-2025-31892
- EPSS 0.21%
- Veröffentlicht 01.04.2025 15:16:32
- Zuletzt bearbeitet 23.04.2026 15:28:29
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding wp-crowdfunding allows Stored XSS.This issue affects WP Crowdfunding: from n/a through <= 2.1.15.
CVE-2025-1508
- EPSS 0.41%
- Veröffentlicht 12.03.2025 03:21:27
- Zuletzt bearbeitet 08.04.2026 18:24:25
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all versions up to, and including, 2.1.14. This makes it possible for authenticated attackers, with...
CVE-2023-41870
- EPSS 0.65%
- Veröffentlicht 13.12.2024 15:15:25
- Zuletzt bearbeitet 28.04.2026 19:21:21
Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.5.
CVE-2024-11911
- EPSS 0.27%
- Veröffentlicht 13.12.2024 09:15:07
- Zuletzt bearbeitet 11.02.2025 14:21:42
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all versions up to, and including, 2.1.12. This makes it possible for ...
CVE-2024-11910
- EPSS 0.31%
- Veröffentlicht 13.12.2024 09:15:06
- Zuletzt bearbeitet 08.04.2026 19:19:50
The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search block in all versions up to, and including, 2.1.15 due to insufficient input sanitization and output escaping. This makes it possible...
CVE-2024-43937
- EPSS 0.36%
- Veröffentlicht 01.11.2024 15:15:49
- Zuletzt bearbeitet 08.11.2024 15:57:27
Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.10.
CVE-2024-10117
- EPSS 0.37%
- Veröffentlicht 26.10.2024 12:15:12
- Zuletzt bearbeitet 11.02.2025 17:47:46
The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate shortcode in all versions up to, and including, 2.1.11 due to insufficient input sanitization and output escaping on user supplied attr...