CVE-2026-14858: CWE-639 Authorization Bypass Through User-Controlled Key in WP Crowdfunding
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.
AI Analysis
Technical Summary
CVE-2026-14858 is an authorization bypass vulnerability in the WP Crowdfunding WordPress plugin prior to version 2.2.1. The plugin does not properly verify that a user owns an order before disclosing order details. This flaw enables any authenticated user, regardless of privilege level, to read personal data associated with any WooCommerce order and to enumerate all orders in the store. The vulnerability is classified under CWE-639 (Authorization Bypass Through User-Controlled Key). No CVSS score or vendor advisory is currently available, and no patch or official remediation has been confirmed.
Potential Impact
Any authenticated user on a WordPress site using a vulnerable version of WP Crowdfunding can access sensitive personal information from WooCommerce orders they do not own. This exposure risks privacy violations and potential misuse of customer data. Additionally, the ability to enumerate all orders could facilitate further targeted attacks or data harvesting.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user roles to trusted users only and consider disabling or limiting the WP Crowdfunding plugin functionality that exposes order details. Monitor for vendor updates and apply patches promptly once released.
CVE-2026-14858: CWE-639 Authorization Bypass Through User-Controlled Key in WP Crowdfunding
Description
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.
CVSS v3.1
Score 4.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-14858 is an authorization bypass vulnerability in the WP Crowdfunding WordPress plugin prior to version 2.2.1. The plugin does not properly verify that a user owns an order before disclosing order details. This flaw enables any authenticated user, regardless of privilege level, to read personal data associated with any WooCommerce order and to enumerate all orders in the store. The vulnerability is classified under CWE-639 (Authorization Bypass Through User-Controlled Key). No CVSS score or vendor advisory is currently available, and no patch or official remediation has been confirmed.
Potential Impact
Any authenticated user on a WordPress site using a vulnerable version of WP Crowdfunding can access sensitive personal information from WooCommerce orders they do not own. This exposure risks privacy violations and potential misuse of customer data. Additionally, the ability to enumerate all orders could facilitate further targeted attacks or data harvesting.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user roles to trusted users only and consider disabling or limiting the WP Crowdfunding plugin functionality that exposes order details. Monitor for vendor updates and apply patches promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-06T12:33:08.237Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7c0e9ebf8831d539143387
Added to database: 08/12/2026, 06:11:42 UTC
Last enriched: 08/12/2026, 06:47:39 UTC
Last updated: 08/13/2026, 00:41:09 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.