AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14857

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The WP Crowdfunding plugin for WordPress prior to version 2.2.1 is vulnerable as it fails to verify the ownership of a campaign, enabling authenticated users, including Subscribers, to modify the update history of other users' campaigns and send notifications to backers. This flaw could lead to unauthorized alterations and misinformation, potentially damaging trust and integrity within the crowdfunding platform. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-14857
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%
WordPress

Original NVD Description

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update history to be modified and a notification email sent to its backers, allowing any authenticated users such as Subscribers to alter other users' campaigns.