WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR
Summary
| CVE | CVE-2026-14858 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-12 06:17:47 UTC |
| Updated | 2026-08-12 06:17:47 UTC |
| Description | The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store. |
Risk And Classification
Problem Types: CWE-639 Authorization Bypass Through User-Controlled Key
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | WP Crowdfunding | affected 2.2.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/59022a2a-29b2-485a-9512-cd0a27b6492b | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Sajjad Haqi (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.