Impact
WP Crowdfunding is a WordPress plugin that facilitates crowdfunding campaigns. Prior to version 2.2.1, the plugin fails to verify that an authenticated user is the owner of a campaign before allowing the update history to be changed or a notification email sent to backers. This oversight lets any user with basic subscription privileges modify another person's campaign details and trigger notifications. The impact is a breach of data integrity for campaign records and the potential for misleading or defrauding backers, as the content and history can be altered without authorization.
Affected Systems
Any WordPress site running the WP Crowdfunding plugin with a version below 2.2.1 is vulnerable. The issue is bound to the plugin itself, regardless of the WordPress core version or other plugins, and affects all instances where the plugin's update endpoints are reachable by authenticated users.
Risk and Exploitability
Because the flaw is an IDOR, the attacker only needs valid credentials, which a subscriber or other role commonly has. No additional exploits or privilege escalation are required, making the vulnerability highly exploitable. The lack of an EPSS score and absence from CISA KEV do not diminish the risk; the integrity and trust of crowdfunding campaigns are directly compromised. Therefore, remediation is critical.
OpenCVE Enrichment