What is CVE-2026-14858?
The WP Crowdfunding plugin for WordPress before version 2.2.1 fails to verify order ownership, allowing any authenticated user, such as Subscribers, to read personal data from any WooCommerce order and enumerate all orders in the store. Affected systems should immediately update the plugin to the latest version.
Azərbaycanca: WP Crowdfunding WordPress plaqini 2.2.1 versiyasından əvvəl sifariş sahibliyini yoxlamır, bu isə Subscribers kimi hər hansı autentifikasiya olunmuş istifadəçiyə mağazadakı bütün WooCommerce sifarişlərinin şəxsi məlumatlarını oxumağa imkan verir. Təsirə məruz qalan sistemlərdə plaqin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
How can an attacker exploit the authorization flaw in WP Crowdfunding plugin versions before 2.2.1?
This vulnerability allows any authenticated user, such as Subscribers, to read personal data from any WooCommerce order and enumerate all orders in the store, because the plugin fails to verify order ownership.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.