CyberRota Analysis
AI-GeneratedThe WP Crowdfunding plugin for WordPress prior to version 2.2.1 is vulnerable due to a lack of order ownership verification, enabling authenticated users, including Subscribers, to access sensitive personal data from any WooCommerce order and enumerate all orders in the store. This could lead to unauthorized data exposure and privacy breaches. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.
Original NVD Description
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.