Description
The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order injection: a Shop Manager writes the malicious payload once via the WooCommerce REST products endpoint (POST/PUT /wp-json/wc/v3/products/{id}), and the injected query executes on every subsequent public page view that renders the campaign rewards sidebar.
Published: 2026-09-09
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Breach via SQL Injection
Action: Apply Patch
AI Analysis

Impact

A second‑order SQL injection exists in WP Crowdfunding that allows authenticated users with shop manager or higher permissions to inject malicious SQL through the WooCommerce REST products endpoint. When the injected content is later rendered on the campaign rewards sidebar, the query runs against the database, enabling the attacker to read sensitive tables. The primary impact is the extraction of confidential information from the WordPress database. The weakness is classified as CWE‑89.

Affected Systems

WordPress sites that use the WP Crowdfunding plugin version 2.2.1 or earlier. The vendor is Themeum. Users possessing shop manager or higher roles on such sites are vulnerable.

Risk and Exploitability

The CVSS score is 4.9, indicating a medium severity. The EPSS score is not provided and the vulnerability is not listed in CISA KEV, so the public exploitation probability is unknown. Exploitation requires authentication with a shop manager or higher role and relies on the WooCommerce REST products endpoint to insert the payload, making the attack vector medium‑risk but still practical for an insider or compromised account.

Generated by OpenCVE AI on September 9, 2026 at 11:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Crowdfunding to the latest version (>=2.2.2) where the injection flaw is fixed.
  • If an immediate upgrade is not possible, disable or restrict the WooCommerce REST products endpoint for shop manager and higher users, or remove those capabilities from the affected role.
  • Sanitize or escape any 'wpneo_reward' post meta values before inserting them into the database, for example by calling esc_sql on the payload or by using a custom filter that validates the input.

Generated by OpenCVE AI on September 9, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum wp Crowdfunding
Wordpress
Wordpress wordpress
Vendors & Products Themeum
Themeum wp Crowdfunding
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order injection: a Shop Manager writes the malicious payload once via the WooCommerce REST products endpoint (POST/PUT /wp-json/wc/v3/products/{id}), and the injected query executes on every subsequent public page view that renders the campaign rewards sidebar.
Title WP Crowdfunding <= 2.2.1 - Authenticated (Shop Manager+) SQL Injection via 'wpneo_reward' Post Meta
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Themeum Wp Crowdfunding
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T13:58:27.522Z

Reserved: 2026-08-15T16:47:14.240Z

Link: CVE-2026-19944

cve-icon Vulnrichment

Updated: 2026-09-09T13:57:54.482Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T04:17:57.613

Modified: 2026-09-09T15:33:34.467

Link: CVE-2026-19944

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T22:30:08Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')