Impact
WP Crowdfunding is a WordPress plugin that facilitates crowdfunding campaigns. Prior to version 2.2.1, the plugin fails to verify that an authenticated user is the owner of a campaign before allowing the update history to be changed or a notification email sent to backers. This oversight lets any user with basic subscription privileges modify another person's campaign details and trigger notifications. The impact is a breach of data integrity for campaign records and the potential for misleading or defrauding backers, as the content and history can be altered without authorization.
Affected Systems
Any WordPress site running the WP Crowdfunding plugin with a version below 2.2.1 is vulnerable. The issue is bound to the plugin itself, regardless of the WordPress core version or other plugins, and affects all instances where the plugin's update endpoints are reachable by authenticated users.
Risk and Exploitability
Because the flaw is an IDOR, the attacker only needs valid credentials, which a subscriber or other role commonly has. No additional exploits or privilege escalation are required, making the vulnerability highly exploitable. The CVSS score of 4.3 reflects a moderate severity, while the EPSS score of < 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but the ease of execution for authenticated users and the potential damage to campaign integrity make it significant for affected sites.
OpenCVE Enrichment