Impact
The vulnerability is an insecure direct object reference that allows an authenticated or unauthenticated user to manipulate a query parameter and retrieve subscriber data that they should not have access to. By changing the numeric ID in the URL, an attacker can read or modify other subscribers’ personal information, resulting in a breach of confidentiality and unauthorized disclosure of sensitive user data.
Affected Systems
Asset owners running the WordPress WP Crowdfunding plugin from Themeum, specifically any installation of the plugin older than version 2.2.1, are affected. The issue exists across all revisions preceding the security release that introduced proper object validation.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. EPSS is not available, so the current probability of exploitation is unknown; however, the attack requires only constructing a URL and may be performed by anyone who knows or guesses a subscriber identifier. Because the flaw is in the application code, the attack vector is likely remote over HTTP/S. The vulnerability is not listed in the CISA KEV catalog, so no confirmed widespread exploitation is reported yet. Nonetheless, the potential for data leaks warrants remediation.
OpenCVE Enrichment