CVE-2026-73993: WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Affected Software
1 affected component
WordPress FundEngine Plugin<=1.7.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress FundEngine pluginto a version that resolves this vulnerability.Fixed in 1.8.0
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. The vector is network-accessible and requires no user interaction.
2
Which installations are affected?
FundEngine versions 1.7.9 and earlier are affected. The provided information does not identify any configuration requirement or mitigation for unpatched installations.
3
What is the potential impact?
The supplied severity metrics indicate high impact to confidentiality, integrity, and availability. Exploitation is rated critical with a 9.8 score.