Impact
The FundEngine plugin for WordPress contains a broken access control flaw that permits an attacker to view or otherwise manipulate subscriber information. The vulnerability is classified as CWE‑862 (Missing Authorization) and is rated a moderate severity (CVSS 6.5). An exploit would allow a compromised or unauthenticated user to gain access to data that should be restricted to privileged users, potentially exposing personally identifiable information stored by the plugin.
Affected Systems
Any WordPress installation that has the Roxnor FundEngine plugin installed with version 1.7.8 or earlier is susceptible. The plugin version number is the only specific version data provided; no further sub‑version details are supplied.
Risk and Exploitability
The CVSS score reflects a moderate risk, and the EPSS score of less than 1% indicates a very low probability of widespread exploitation at present. vulnerability is not listed in the CISA KEV catalog. Based on the description of a broken access control mechanism, the likely attack vector involves interaction with the plugin’s web interface, where missing authorization checks allow users to access subscriber data that should be protected. This inference is drawn from the nature of the flaw and does not imply confirmed exploitation activity.
OpenCVE Enrichment