Impact
A missing capability check in the WP Crowdfunding plugin allows any authenticated user, such as a subscriber, to submit a crowdfunding campaign through an AJAX action. The attacker can create campaigns without the proper authorisation, potentially flooding the site with spam or malicious content and undermining the site’s integrity.
Affected Systems
WordPress installations running the WP Crowdfunding plugin before release 2.2.1 are affected. The vulnerability resides in the plugin’s AJAX handling code and applies to any site where the plugin is active and users can authenticate.
Risk and Exploitability
The flaw is exploitable only by users who are already logged in, which limits the threat to accounts that have any level of authentication. The EPSS score is not available and the issue is not listed in CISA KEV, but the lack of authorisation checks represents a high‑severity risk because it permits the unrestricted creation of campaign posts. It is recommended to treat this as a high‑impact issue given its potential to affect site content and reputation.
OpenCVE Enrichment