CVE-2026-14859

The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as Subscribers to create crowdfunding campaign posts despite not being granted that permission.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-14859

Mitre link : CVE-2026-14859

CVE.ORG link : CVE-2026-14859


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control