Description
The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An administrator viewing any user's profile via the ?show_user_id= parameter will render the attacker's stored payload in the admin's browser session, enabling cross-privilege script execution.
Published: 2026-09-09
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting leading to cross‑privilege script execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an authenticated user with subscriber‑level permissions to store arbitrary JavaScript in the 'first_name' field of a user profile. When an administrator later views that profile, the stored script runs in the administrator's browser session, enabling an attacker to execute scripts with the administrator's privileges. This is a stored cross‑site scripting flaw classified as CWE‑79 and can be used to hijack admin sessions, deface pages, or steal sensitive information that the administrator can see.

Affected Systems

WordPress plugin WP Crowdfunding, all versions up to and including 2.2.1. The flaw exists in every installation of the plugin in those releases and will persist until the plugin is upgraded or the data causing the injection is removed.

Risk and Exploitability

The CVSS score is 6.4 and no EPSS score is available. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires an authenticated account with at least subscriber privileges; the attacker can inject malicious JavaScript that will be executed whenever an administrator views the affected user's profile. The attack vector is authenticated code injection via the plugin’s user interface, representing a moderate to high risk for sites that use the affected plugin version.

Generated by OpenCVE AI on September 9, 2026 at 11:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Crowdfunding plugin to the latest release (2.2.2 or higher) which removes the unsafe handling of the 'first_name' field.
  • If an upgrade cannot be performed immediately, reset or delete any stored 'first_name' values that contain suspicious characters or script tags to eliminate the stored payload.
  • As a temporary containment measure, restrict subscriber‑level access to profile editing features or enforce a site‑wide web application firewall rule that blocks known XSS patterns on the 'first_name' input field.

Generated by OpenCVE AI on September 9, 2026 at 11:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum wp Crowdfunding
Wordpress
Wordpress wordpress
Vendors & Products Themeum
Themeum wp Crowdfunding
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An administrator viewing any user's profile via the ?show_user_id= parameter will render the attacker's stored payload in the admin's browser session, enabling cross-privilege script execution.
Title WP Crowdfunding <= 2.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'first_name' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Themeum Wp Crowdfunding
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T13:09:44.259Z

Reserved: 2026-08-15T16:49:20.181Z

Link: CVE-2026-19945

cve-icon Vulnrichment

Updated: 2026-09-09T13:09:38.292Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T05:17:20.207

Modified: 2026-09-09T15:33:34.467

Link: CVE-2026-19945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T22:15:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')