CVE-2026-14859
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
12/08/2026
Last modified:
12/08/2026
Description
The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as Subscribers to create crowdfunding campaign posts despite not being granted that permission.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM



