What is CVE-2026-14859?
The WP Crowdfunding WordPress plugin before version 2.2.1 fails to check the campaign-submission capability in one of its AJAX actions. This allows any authenticated user, such as a Subscriber, to create crowdfunding campaign posts without proper permission. Updating to the latest version is recommended.
Azərbaycanca: WP Crowdfunding WordPress plaginində CVE-2026-14859 zəifliyi aşkarlanıb. 2.2.1 versiyasından əvvəlki versiyalarda, "campaign-submission" icazəsi yoxlanılmadığı üçün Subscriber kimi autentifikasiya olunmuş istənilən istifadəçi AJAX əməliyyatı vasitəsilə icazəsiz crowdfunding kampaniyası yarada bilir. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What user role can exploit the CVE-2026-14859 vulnerability in the WP Crowdfunding plugin?
Any authenticated user, such as a Subscriber, can exploit this vulnerability.
How can the CVE-2026-14859 vulnerability be fixed?
Updating the WP Crowdfunding plugin to version 2.2.1 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.