Executive brief
Roxnor FundEngine, a WordPress plugin used for managing fundraising and donations, contains a security flaw in its access control settings. An unauthorized user could exploit this to perform actions they should not be allowed to, potentially interfering with donation management or site operations. This could lead to unauthorized changes to fundraising data or service disruptions.
Technical details
A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the Roxnor FundEngine (wp-fundraising-donation) plugin for WordPress. The flaw stems from incorrectly configured access control security levels, which fail to validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to perform actions typically reserved for higher-privileged users. The vulnerability affects all versions up to and including 1.7.6. A fix is available in version 1.7.7.
Affected products
- Roxnor FundEngine (wp-fundraising-donation) <= 1.7.6
Timeline
- 2026-04-29: disclosed: Reported by Peng Zhou
- 2026-07-08: advisory: Patchstack advisory published
- 2026-07-13: advisory: NVD published date
- 2026-07-08: patched: Version 1.7.7 released to address the issue