Executive brief
FundEngine, a WordPress plugin used for managing fundraising and donations, contains a security flaw that allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to access. This could allow a low-level user to interfere with the plugin's operations, potentially leading to a service disruption or unauthorized changes to fundraising activities. Organizations using this plugin should update to the latest version to ensure only authorized administrators can manage donation settings.
Technical details
The FundEngine plugin (wp-fundraising-donation) for WordPress, versions up to and including 1.7.8, suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). An attacker authenticated with a low-level 'Subscriber' role can exploit this flaw to execute functions or access endpoints that should be restricted to higher-privileged users. According to the CVSS vector, the primary impact is on availability (A:H), suggesting that unauthorized access could be used to disrupt plugin functionality. The issue is resolved in version 1.7.9.
Affected products
- Roxnor FundEngine (wp-fundraising-donation) <= 1.7.8
Timeline
- 2026-05-26: other: Reported by Septio Noerdiansyah
- 2026-07-27: advisory: Published by Patchstack and NVD
- 2026-07-27: patched: Version 1.7.9 released to address the vulnerability