CVE-2026-14859: WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Creation via Missing Authorization
The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as Subscribers to create crowdfunding campaign posts despite not being granted that permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14859?
CVE-2026-14859 has a risk score of 43, indicating a significant security vulnerability.
How does CVE-2026-14859 affect users of the WP Crowdfunding plugin?
CVE-2026-14859 allows any authenticated user, including Subscribers, to create crowdfunding campaign posts without appropriate permissions.
What versions of WP Crowdfunding are vulnerable to CVE-2026-14859?
WP Crowdfunding versions prior to 2.2.1 are vulnerable to CVE-2026-14859.
How do I fix CVE-2026-14859?
To fix CVE-2026-14859, you should update the WP Crowdfunding plugin to version 2.2.1 or later.
What type of users are affected by CVE-2026-14859?
CVE-2026-14859 affects authenticated users with Subscriber roles, allowing them to create unauthorized campaigns.