Description
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The FundEngine plugin for WordPress contains a broken access control flaw that permits an attacker to view or otherwise manipulate subscriber information. The vulnerability is classified as CWE‑862 (Missing Authorization) and is rated a moderate severity (CVSS 6.5). An exploit would allow a compromised or unauthenticated user to gain access to data that should be restricted to privileged users, potentially exposing personally identifiable information stored by the plugin.

Affected Systems

Any WordPress installation that has the Roxnor FundEngine plugin installed with version 1.7.8 or earlier is susceptible. The plugin version number is the only specific version data provided; no further sub‑version details are supplied.

Risk and Exploitability

The CVSS score reflects a moderate risk, and the EPSS score of less than 1% indicates a very low probability of widespread exploitation at present. vulnerability is not listed in the CISA KEV catalog. Based on the description of a broken access control mechanism, the likely attack vector involves interaction with the plugin’s web interface, where missing authorization checks allow users to access subscriber data that should be protected. This inference is drawn from the nature of the flaw and does not imply confirmed exploitation activity.

Generated by OpenCVE AI on August 3, 2026 at 17:32 UTC.

Remediation

Vendor Solution

Update the WordPress FundEngine Plugin to the latest available version (at least 1.7.9).


OpenCVE Recommended Actions

  • Upgrade the WordPress FundEngine Plugin to version 1.7.9 or later, which includes the access‑control fix.
  • If an upgrade is not immediately possible, disable the plugin or remove it from the live site to prevent unauthorized access to subscriber data.
  • Monitor WordPress logs and user activity for attempts to access subscriber information and review access permissions regularly.

Generated by OpenCVE AI on August 3, 2026 at 17:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Roxnor
Roxnor fundengine
Wordpress
Wordpress wordpress
Vendors & Products Roxnor
Roxnor fundengine
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
Title WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Roxnor Fundengine
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:17:54.008Z

Reserved: 2026-07-05T21:28:04.587Z

Link: CVE-2026-59560

cve-icon Vulnrichment

Updated: 2026-07-27T15:12:48.071Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:06.303

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-59560

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses