Description
The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover.
Published: 2026-10-11
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The Crowdfundly WordPress plugin through version 2.2.2 lacks capability checks on certain AJAX actions. A user with a low‑privileged role can exploit these actions to grant themselves the administrator role or arbitrary capabilities, effectively allowing a full takeover of the site.

Affected Systems

Any installation of the Crowdfundly plugin on a WordPress site version 2.2.2 or earlier is affected. The culprit is the plugin itself, provided by the vendor Crowdfundly.

Risk and Exploitability

The vulnerability has a CVSS score of 7.2, indicating high severity, and an EPSS score of less than 1 %, implying a low overall likelihood of exploitation. Because any user who can log in with a low‑privileged role can trigger the unprotected AJAX actions, the attack vector is internal and relatively simple. Gaining administrator rights via the privilege escalation grants full control over the WordPress site, making the potential impact severe.

Generated by OpenCVE AI on October 11, 2026 at 14:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Crowdfundly plugin to the latest version that includes the missing capability checks
  • If an upgrade is not possible, disable or remove the vulnerable AJAX actions to prevent privilege escalation, or deactivate the plugin entirely until a fix is applied
  • Audit existing user roles and revoke any accidental administrator privileges that may have been granted by the exploit

Generated by OpenCVE AI on October 11, 2026 at 14:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover.
Title Crowdfundly <= 2.2.2 - Crowdfundly Manager+ Privilege Escalation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:44.130Z

Reserved: 2026-09-03T08:38:51.064Z

Link: CVE-2026-85126

cve-icon Vulnrichment

Updated: 2026-10-11T11:23:02.339Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:26.113

Modified: 2026-10-11T12:17:24.370

Link: CVE-2026-85126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-285

    Improper Authorization