AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14859

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The WP Crowdfunding plugin for WordPress prior to version 2.2.1 is vulnerable as it fails to properly validate user permissions during AJAX actions, allowing authenticated users, including those with Subscriber roles, to create crowdfunding campaign posts without the necessary permissions. This flaw could lead to unauthorized content creation, potentially compromising the integrity of crowdfunding campaigns on affected sites. WordPress site administrators using this plugin should prioritize updating to version 2.2.1 or later to mitigate this risk.

CVE
CVE-2026-14859
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%
WordPress

Original NVD Description

The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as Subscribers to create crowdfunding campaign posts despite not being granted that permission.