CVE-2026-32470: WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Affected Software
1 affected component
WordPress FundEngine Plugin<=1.7.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress FundEngine pluginto a version that resolves this vulnerability.Fixed in 1.8.0
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to exploitation?
Sites running FundEngine version 1.7.9 or earlier are affected. The issue is remotely exploitable without authentication or user interaction, so any publicly reachable installation should be treated as exposed.
2
What access does an attacker need?
An attacker does not need an account or prior privileges. The vector is network-accessible and the impact rating indicates potential compromise of confidentiality, integrity, and availability.