Junglewise Threat Intelligence

CVE-2026-57406: Roxnor FundEngine missing authorization in wp-fundraising-donation

CVE-2026-57406 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Technologies: Roxnor FundEngine. Vendors: Roxnor.

Executive brief

Roxnor FundEngine, a WordPress plugin used for managing fundraising and donations, contains a security flaw in its access control settings. An unauthorized user could exploit this to perform actions they should not be allowed to, potentially interfering with donation management or site operations. This could lead to unauthorized changes to fundraising data or service disruptions.

Technical details

A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the Roxnor FundEngine (wp-fundraising-donation) plugin for WordPress. The flaw stems from incorrectly configured access control security levels, which fail to validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to perform actions typically reserved for higher-privileged users. The vulnerability affects all versions up to and including 1.7.6. A fix is available in version 1.7.7.

Affected products

  • Roxnor FundEngine (wp-fundraising-donation) <= 1.7.6

Timeline

  • 2026-04-29: disclosed: Reported by Peng Zhou
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published date
  • 2026-07-08: patched: Version 1.7.7 released to address the issue

References

Related threats