Junglewise Threat Intelligence

CVE-2026-73993: FundEngine PHP object injection

CVE-2026-73993 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Executive brief

FundEngine is a WordPress plugin for fundraising and donations. An unauthenticated attacker can exploit a PHP object injection vulnerability to execute arbitrary code on affected websites, potentially compromising site data, disrupting operations, and enabling further attacks against visitors and site infrastructure.

Technical details

The vulnerability is a PHP object injection (deserialization) flaw in FundEngine versions 1.7.9 and earlier. It allows unauthenticated network-based attackers to manipulate how the plugin processes serialized data, leading to arbitrary code execution on the server. No authentication or user interaction is required to exploit this vulnerability. An attacker can leverage this to run malicious code with the web server's privileges, compromising the entire site. The vulnerability was patched in version 1.8.0.

Affected products

  • FundEngine FundEngine <=1.7.9

Timeline

  • 2026-08-20: disclosed
  • 2026-08-19: patched: Version 1.8.0

References