Executive brief
The Cryptocurrency Donation Box plugin for WordPress, which allows site owners to accept digital currency donations, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to perform actions that should be restricted to administrators or specific users. While the impact is considered limited, it could allow attackers to modify plugin settings or interfere with the donation interface without permission.
Technical details
A missing authorization (CWE-862) vulnerability exists in the AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin for WordPress through version 2.2.13. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to perform unauthorized actions or modify plugin configurations. As of the advisory date, no official patch has been released, and the vulnerability affects all versions up to 2.2.13.
Affected products
- AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations <= 2.2.13
Timeline
- 2026-01-24: other: Vulnerability reported by researcher Nabil Irawan
- 2026-02-23: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD