Junglewise Threat Intelligence

CVE-2026-32470: WordPress FundEngine PHP object injection

CVE-2026-32470 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Executive brief

FundEngine is a WordPress plugin for fundraising and donations. An unauthenticated PHP object injection vulnerability allows attackers to manipulate how the site processes data and execute arbitrary actions on the server without requiring authentication, potentially leading to complete site compromise.

Technical details

The vulnerability is a PHP object injection flaw in the FundEngine WordPress plugin versions 1.7.9 and earlier. It can be exploited without authentication, allowing attackers to inject malicious serialized objects that are deserialized by the application. This enables arbitrary code execution and full server compromise. The vulnerability was patched in version 1.8.0. The attack vector is network-based with no authentication requirement, making it highly exploitable at scale.

Affected products

  • FundEngine FundEngine <=1.7.9

Timeline

  • 2026-08-18: disclosed
  • 2026-08-14: patched: Fixed in version 1.8.0

References