Impact
A second‑order SQL injection exists in WP Crowdfunding that allows authenticated users with shop manager or higher permissions to inject malicious SQL through the WooCommerce REST products endpoint. When the injected content is later rendered on the campaign rewards sidebar, the query runs against the database, enabling the attacker to read sensitive tables. The primary impact is the extraction of confidential information from the WordPress database. The weakness is classified as CWE‑89.
Affected Systems
WordPress sites that use the WP Crowdfunding plugin version 2.2.1 or earlier. The vendor is Themeum. Users possessing shop manager or higher roles on such sites are vulnerable.
Risk and Exploitability
The CVSS score is 4.9, indicating a medium severity. The EPSS score is not provided and the vulnerability is not listed in CISA KEV, so the public exploitation probability is unknown. Exploitation requires authentication with a shop manager or higher role and relies on the WooCommerce REST products endpoint to insert the payload, making the attack vector medium‑risk but still practical for an insider or compromised account.
OpenCVE Enrichment