Executive brief
The WP Crowdfunding plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability that allows attackers with subscriber-level access to inject malicious scripts into user profiles via the first name field. When administrators view an affected user's profile, the injected script executes in their browser session, potentially allowing attackers to perform administrative actions or steal sensitive data.
Technical details
The vulnerability is a stored cross-site scripting flaw in the WP Crowdfunding plugin caused by insufficient input sanitization and output escaping of the 'first_name' parameter. Authenticated attackers with subscriber-level access and above can inject arbitrary JavaScript code that persists in the database. The payload executes when any user (including administrators) accesses the injected user profile via the ?show_user_id= parameter, enabling cross-privilege script execution within the admin's session. This affects all versions up to and including 2.2.1. A patch or update is required to properly sanitize and escape the affected parameter.
Affected products
- WP Crowdfunding WP Crowdfunding up to and including 2.2.1
Timeline
- 2026-09-09: disclosed