Description
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all versions up to, and including, 2.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to download all of a site's post content when WooCommerce is installed.
Problem types
Product status
* (semver)
Timeline
| 2025-03-11: | Disclosed |
Credits
Krzysztof Zając
References
www.wordfence.com/...-9801-41d2-8923-ca4ae6ae974f?source=cve
wordpress.org/plugins/wp-crowdfunding/