Extension WordPress

Vulnérabilités FundEngine – Donation and Crowdfunding Platform

Cette page rassemble les failles publiées pour FundEngine – Donation and Crowdfunding Platform, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
1Critiques
6Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de FundEngine – Donation and Crowdfunding Platform

6 fiches

CVE-2026-57406 Moyenne · 5,3
FundEngine – Donation and Crowdfunding Platform

FundEngine – Donation and Crowdfunding Platform <= 1.7.6 – Missing Authorization

The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.6. This makes it possible for unauthenticated attackers…

Versions affectées

*-1.7.6

Correctif

1.7.7

Publication

08/07/2026

CVE-2025-48302 Élevée · 7,5
FundEngine – Donation and Crowdfunding Platform

FundEngine <= 1.7.4 – Authenticated (Subscriber+) Local File Inclusion

The FundEngine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the…

Versions affectées

*-1.7.4

Correctif

1.7.5

Publication

08/08/2025

CVE-2025-47459 Moyenne · 4,3
FundEngine – Donation and Crowdfunding Platform

WP Fundraising Donation and Crowdfunding Platform <= 1.7.3 – Cross-Site Request Forgery

The WP Fundraising Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.3. This is due to missing or incorrect nonce validation on the wfp_donate_settings() function. This makes…

Versions affectées

*-1.7.3

Correctif

1.7.4

Publication

07/05/2025

CVE-2024-6698 Élevée · 8,8
FundEngine – Donation and Crowdfunding Platform

FundEngine – Donation and Crowdfunding Platform <= 1.7.0 – Authenticated (Subscriber+) Privilege Escalation

The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible…

Versions affectées

*-1.7.0

Correctif

1.7.1

Publication

31/07/2024

CVE-2024-34758 Moyenne · 5,3
FundEngine – Donation and Crowdfunding Platform

WP Fundraising Donation and Crowdfunding Platform <= 1.6.4 – Missing Authorization

The WP Fundraising Donation and Crowdfunding Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions surrounding donation modification in versions up to, and including, 1.6.4. This makes…

Versions affectées

*-1.6.4

Correctif

1.7.0

Publication

14/05/2024

CVE-2022-0788 Critique · 9,8
FundEngine – Donation and Crowdfunding Platform

WP Fundraising Donation and Crowdfunding Platform <= 1.4.2 – Unauthenticated SQL Injection

The WP Fundraising Donation and Crowdfunding Platform WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by…

Versions affectées

*-1.4.2

Correctif

1.5.0

Publication

11/05/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités