Junglewise Threat Intelligence

CVE-2026-14857: WP Crowdfunding campaign update modification via insecure direct object reference

CVE-2026-14857 · Severity: medium · CVSS 4.3 · Published 2026-08-12

Technologies: WP Crowdfunding. Vendors: WP Crowdfunding.

Executive brief

WP Crowdfunding is a popular WordPress plugin used to create and manage crowdfunding campaigns. The plugin fails to verify that a user owns a campaign before allowing updates to its history and notifications, enabling any logged-in subscriber to modify other users' campaigns and send fraudulent emails to backers impersonating legitimate campaign owners.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) in the campaign update functionality. The plugin's wpneo_update_status_save AJAX action does not properly validate campaign ownership before processing updates to campaign history metadata and sending notification emails to backers. An authenticated user with only Subscriber privileges can craft a POST request to wp-admin/admin-ajax.php with a nonce harvested from the public dashboard, substituting any campaign's post ID to modify its update history and trigger fraudulent notifications. The attacker's content is persisted in campaign meta and distributed to all backers via email, appearing to come from the legitimate campaign owner.

Affected products

  • WP Crowdfunding WP Crowdfunding before 2.2.1

Timeline

  • 2026-08-10: disclosed
  • 2026-08-12: patched: Fixed in version 2.2.1

References

Related threats