Impact
The Roxnor FundEngine WordPress plugin contains a missing authorization check that permits users with insufficient privileges to access functions meant for higher‑level accounts. This flaw, classified as CWE‑862, could lead to unauthorized review or alteration of donation data and the manipulation of fundraising campaign settings. The impact is confined to data confidentiality and integrity; there is no evidence of code execution or denial‑of‑service capability.
Affected Systems
All installations of the Roxnor FundEngine WordPress plugin with a version of 1.7.6 or earlier are affected. The vulnerability applies to every release from the plugin’s first available version up to and including 1.7.6.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation currently. The issue is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the plugin’s web interface, where an attacker can submit crafted requests to endpoints that lack proper role checks or exploit an existing session with insufficient privileges. No remote code execution or denial‑of‑service abilities are described, so the risk is limited to unauthorized data access or manipulation.
OpenCVE Enrichment