What is CVE-2026-14857?
The WP Crowdfunding WordPress plugin before version 2.2.1 does not verify campaign ownership, allowing any authenticated user (such as a Subscriber) to modify update history and send notification emails to backers of other users' campaigns. Affected sites should immediately update the plugin to version 2.2.1 or later to patch this vulnerability.
Azərbaycanca: WP Crowdfunding WordPress plaqinində autentifikasiya olunmuş istənilən istifadəçi (məsələn, Subscriber) kampaniya sahibliyini yoxlamadan digər istifadəçilərin kampaniya yeniləmə tarixçəsini dəyişdirə və dəstəkçilərə saxta bildiriş e-poçtu göndərə bilər. Plaqinin 2.2.1-dən əvvəlki versiyaları təsirlənir, ona görə də dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What unauthorized actions can an authenticated user perform in the WP Crowdfunding plugin?
Any authenticated user (such as a Subscriber) can modify the campaign update history and send notification emails to backers of other users' campaigns without verifying campaign ownership.
To which version should the WP Crowdfunding plugin be updated to fix CVE-2026-14857?
Since versions before 2.2.1 are affected, it is recommended to immediately update the plugin to version 2.2.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.