Junglewise Threat Intelligence

CVE-2026-76063: FundEngine Stored Cross-Site Scripting in featured video URL

CVE-2026-76063 · Severity: medium · CVSS 6.4 · Published 2026-08-25

Executive brief

The FundEngine plugin, a WordPress donation and crowdfunding platform used by organizations to collect funds online, is vulnerable to stored cross-site scripting (XSS). Attackers with subscriber-level access or higher can inject malicious scripts that execute when other users view affected pages, potentially stealing session credentials, redirecting users to malicious sites, or compromising the integrity of donation pages.

Technical details

The vulnerability is a stored XSS flaw in the 'wfp_featured_video_url' parameter caused by insufficient input sanitization and output escaping in the FundEngine plugin. The vulnerable REST endpoint uses permission_callback set to __return_true, allowing any authenticated user (including those with subscriber-level access) to submit arbitrary data. An attacker can inject malicious JavaScript via the video URL field, which is then stored in the database and executed in the browsers of all users who access the affected page. The vulnerability affects all versions up to and including 1.8.1; patches or updated versions should be applied immediately.

Affected products

  • FundEngine FundEngine – Donation and Crowdfunding Platform up to and including 1.8.1

Timeline

  • 2026-08-25: disclosed

References