Description
Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Roxnor FundEngine WordPress plugin contains a missing authorization check that permits users with insufficient privileges to access functions meant for higher‑level accounts. This flaw, classified as CWE‑862, could lead to unauthorized review or alteration of donation data and the manipulation of fundraising campaign settings. The impact is confined to data confidentiality and integrity; there is no evidence of code execution or denial‑of‑service capability.

Affected Systems

All installations of the Roxnor FundEngine WordPress plugin with a version of 1.7.6 or earlier are affected. The vulnerability applies to every release from the plugin’s first available version up to and including 1.7.6.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation currently. The issue is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the plugin’s web interface, where an attacker can submit crafted requests to endpoints that lack proper role checks or exploit an existing session with insufficient privileges. No remote code execution or denial‑of‑service abilities are described, so the risk is limited to unauthorized data access or manipulation.

Generated by OpenCVE AI on July 31, 2026 at 11:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the FundEngine plugin to a version newer than 1.7.6 if one is available.
  • If an upgrade cannot be applied immediately, temporarily disable or uninstall the plugin to block potential exploitation.
  • Review WordPress role definitions and enforce strict least‑privilege policies so that only trusted administrators can access donation management features.

Generated by OpenCVE AI on July 31, 2026 at 11:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Roxnor
Roxnor fundengine
Wordpress
Wordpress wordpress
Vendors & Products Roxnor
Roxnor fundengine
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6.
Title WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Roxnor Fundengine
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:41:42.672Z

Reserved: 2026-06-24T12:46:27.804Z

Link: CVE-2026-57406

cve-icon Vulnrichment

Updated: 2026-07-13T13:41:39.293Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses