CVE-2026-14859
Deferred Deferred - Pending Action

WP Crowdfunding Plugin Unauthorized Campaign Creation Vulnerability

Vulnerability report for CVE-2026-14859, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-26

Assigner: WPScan

Description

The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as Subscribers to create crowdfunding campaign posts despite not being granted that permission.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-26
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_crowdfunding wp_crowdfunding to 2.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-14859 is a vulnerability in the WP Crowdfunding WordPress plugin before version 2.2.1. It allows any authenticated user, including those with Subscriber-level access, to create crowdfunding campaign posts without proper permission checks. This occurs due to a missing capability check in one of the plugin's AJAX actions.

Detection Guidance

Check the installed version of the WP Crowdfunding plugin. If it is below 2.2.1, the system is vulnerable. Look for unauthorized crowdfunding campaign posts created by Subscriber-level users.

Impact Analysis

This vulnerability allows unauthorized users to create crowdfunding campaigns on your WordPress site. This could lead to spam campaigns, fraudulent activities, or misuse of your site's crowdfunding functionality. It undermines the intended access controls and may disrupt legitimate campaign management.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized users to create crowdfunding campaigns. Unauthorized campaign creation may lead to improper handling of sensitive user data, violating data protection requirements under these regulations.

Mitigation Strategies

Update the WP Crowdfunding plugin to version 2.2.1 or later immediately. Review all crowdfunding campaign posts for unauthorized submissions and remove any suspicious ones.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14859. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart