Executive brief
WP Crowdfunding is a popular WordPress plugin that manages crowdfunding campaigns and rewards. A SQL injection vulnerability allows shop managers to inject malicious database queries through the WooCommerce REST API, which are then executed whenever the campaign rewards sidebar is viewed by any site visitor. This could expose sensitive customer data, order information, or other confidential database records.
Technical details
The vulnerability is a second-order SQL injection in the 'wpneo_reward' post meta handling within the rewards sidebar template. A shop manager or higher privilege user can inject malicious SQL payloads via the WooCommerce REST API endpoint (POST/PUT /wp-json/wc/v3/products/{id}), which are stored unsafely in the database. When any public page renders the campaign rewards sidebar, the injected query executes without proper escaping or prepared statements. The root cause is insufficient input sanitization and lack of parameterized queries. An attacker with shop manager-level or administrator access can extract sensitive information from the WordPress database by crafting specially-crafted reward metadata.
Affected products
- Themesquad WP Crowdfunding up to and including 2.2.1
Timeline
- 2026-09-09: disclosed