Junglewise Threat Intelligence

CVE-2026-59560: Roxnor FundEngine broken access control in WordPress plugin

CVE-2026-59560 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Technologies: Roxnor FundEngine. Vendors: Roxnor.

Executive brief

FundEngine, a WordPress plugin used for managing fundraising and donations, contains a security flaw that allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to access. This could allow a low-level user to interfere with the plugin's operations, potentially leading to a service disruption or unauthorized changes to fundraising activities. Organizations using this plugin should update to the latest version to ensure only authorized administrators can manage donation settings.

Technical details

The FundEngine plugin (wp-fundraising-donation) for WordPress, versions up to and including 1.7.8, suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). An attacker authenticated with a low-level 'Subscriber' role can exploit this flaw to execute functions or access endpoints that should be restricted to higher-privileged users. According to the CVSS vector, the primary impact is on availability (A:H), suggesting that unauthorized access could be used to disrupt plugin functionality. The issue is resolved in version 1.7.9.

Affected products

  • Roxnor FundEngine (wp-fundraising-donation) <= 1.7.8

Timeline

  • 2026-05-26: other: Reported by Septio Noerdiansyah
  • 2026-07-27: advisory: Published by Patchstack and NVD
  • 2026-07-27: patched: Version 1.7.9 released to address the vulnerability

References

Related threats