Description
Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13.
Published: 2026-04-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Apply Patch
AI Analysis

Impact

This vulnerability is a missing authorization flaw in the Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin. It enables an attacker to gain unauthorized access to the plugin’s configuration and potentially tamper with donation settings. The flaw is categorized as CWE‑862 – Missing Authorization. Unauthorized manipulation could compromise the integrity of the donation process and may allow a malicious actor to redirect funds or alter the displayed donation options.

Affected Systems

The issue affects the AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin for WordPress. All releases up to and including version 2.2.13 are vulnerable, meaning any site running one of those versions is at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, while the EPSS score of less than 1% suggests that exploitation is unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, the attack vector is web‑based and requires the ability to send specially crafted HTTP requests to the WordPress site, which an attacker may achieve if they have any level of access to the web application or through phishing. Once accessed, an unprivileged user could modify donation settings without authentication.

Generated by OpenCVE AI on April 13, 2026 at 21:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin to the latest available version (≥ 2.2.14).
  • If an immediate upgrade is not feasible, temporarily disable the plugin until a patched version is applied.
  • Review donation logs and configuration to detect any unauthorized changes and restore proper settings if necessary.

Generated by OpenCVE AI on April 13, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Adastracrypto
Adastracrypto cryptocurrency Donation Box – Bitcoin & Crypto Donations
Wordpress
Wordpress wordpress
Vendors & Products Adastracrypto
Adastracrypto cryptocurrency Donation Box – Bitcoin & Crypto Donations
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13.
Title WordPress Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin <= 2.2.13 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Adastracrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:52:03.971Z

Reserved: 2026-04-07T10:58:10.483Z

Link: CVE-2026-39691

cve-icon Vulnrichment

Updated: 2026-04-13T18:18:26.932Z

cve-icon NVD

Status : Deferred

Published: 2026-04-08T09:16:41.370

Modified: 2026-04-24T18:05:35.730

Link: CVE-2026-39691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:38:30Z

Weaknesses