Impact
A missing capability check in the WP Crowdfunding plugin allows any authenticated user, such as a subscriber, to submit a crowdfunding campaign through an AJAX action. The attacker can create campaigns without the proper authorisation, potentially flooding the site with spam or malicious content and undermining the site’s integrity.
Affected Systems
WordPress installations running the WP Crowdfunding plugin before release 2.2.1 are affected. The vulnerability resides in the plugin’s AJAX handling code and applies to any site where the plugin is active and users can authenticate.
Risk and Exploitability
The flaw is exploitable only by users who are already logged in, which limits the threat to accounts that have any level of authentication. The CVSS score is 4.3, the EPSS score is <1%, and the issue is not listed in CISA KEV. The missing authorization check allows unrestricted creation of campaign posts but the moderate score reflects a moderate severity. It is recommended to treat this as a moderate‑impact issue given its potential to affect site content and reputation.
OpenCVE Enrichment