AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14858

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The WP Crowdfunding plugin for WordPress prior to version 2.2.1 is vulnerable due to a lack of order ownership verification, enabling authenticated users, including Subscribers, to access sensitive personal data from any WooCommerce order and enumerate all orders in the store. This could lead to unauthorized data exposure and privacy breaches. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-14858
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
WordPress

Original NVD Description

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.