CVE-2025-1508: WP Crowdfunding <= 2.1.14 - Missing Authorization to Authenticated (Subscriber+) Post Content Download
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the downloaddata action in all versions up to, and including, 2.1.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to download all of a site's post content when WooCommerce is installed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1508?
CVE-2025-1508 is considered a high severity vulnerability due to the risk of unauthorized data access.
How do I fix CVE-2025-1508?
To fix CVE-2025-1508, you should update the WP Crowdfunding plugin to the latest version beyond 2.1.13.
What versions are affected by CVE-2025-1508?
CVE-2025-1508 affects all versions of the WP Crowdfunding plugin up to and including version 2.1.13.
Who can exploit CVE-2025-1508?
CVE-2025-1508 can be exploited by authenticated attackers with subscriber-level access and above.
What does CVE-2025-1508 allow an attacker to do?
CVE-2025-1508 allows attackers to access sensitive data due to a missing capability check in the download_data action.