{"api_version":"1","generated_at":"2026-08-12T11:38:36+00:00","cve":"CVE-2026-14858","urls":{"html":"https://cve.report/CVE-2026-14858","api":"https://cve.report/api/cve/CVE-2026-14858.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-14858","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-14858"},"summary":{"title":"WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR","description":"The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-12 06:17:47","updated_at":"2026-08-12 06:17:47"},"problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/59022a2a-29b2-485a-9512-cd0a27b6492b/","name":"https://wpscan.com/vulnerability/59022a2a-29b2-485a-9512-cd0a27b6492b/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-14858","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14858","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"WP Crowdfunding","version":"affected 2.2.1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Sajjad Haqi","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"WP Crowdfunding","vendor":"Unknown","versions":[{"lessThan":"2.2.1","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Sajjad Haqi"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store."}],"problemTypes":[{"descriptions":[{"description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-12T06:00:13.076Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/59022a2a-29b2-485a-9512-cd0a27b6492b/"}],"source":{"discovery":"EXTERNAL"},"title":"WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-14858","datePublished":"2026-08-12T06:00:13.076Z","dateReserved":"2026-07-06T12:33:08.237Z","dateUpdated":"2026-08-12T06:00:13.076Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-12 06:17:47","lastModifiedDate":"2026-08-12 06:17:47","problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"14858","Ordinal":"1","Title":"WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via ","CVE":"CVE-2026-14858","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"14858","Ordinal":"1","NoteData":"The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.","Type":"Description","Title":"WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via "}]}}}