Impact
The Crowdfundly WordPress plugin through version 2.2.2 lacks capability checks on certain AJAX actions. A user with a low‑privileged role can exploit these actions to grant themselves the administrator role or arbitrary capabilities, effectively allowing a full takeover of the site.
Affected Systems
Any installation of the Crowdfundly plugin on a WordPress site version 2.2.2 or earlier is affected. The culprit is the plugin itself, provided by the vendor Crowdfundly.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2, indicating high severity, and an EPSS score of less than 1 %, implying a low overall likelihood of exploitation. Because any user who can log in with a low‑privileged role can trigger the unprotected AJAX actions, the attack vector is internal and relatively simple. Gaining administrator rights via the privilege escalation grants full control over the WordPress site, making the potential impact severe.
OpenCVE Enrichment