CyberRota Analysis
AI-GeneratedThe WP Crowdfunding plugin for WordPress prior to version 2.2.1 is vulnerable as it fails to verify the ownership of a campaign, enabling authenticated users, including Subscribers, to modify the update history of other users' campaigns and send notifications to backers. This flaw could lead to unauthorized alterations and misinformation, potentially damaging trust and integrity within the crowdfunding platform. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update history to be modified and a notification email sent to its backers, allowing any authenticated users such as Subscribers to alter other users' campaigns.