WordPress security by component
FundEngine
Plugin description
FundEngine is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
wp-fundraising-donationLatest vulnerability
CVE-2026-59560: FundEngine subscribers can reach a privileged operation
FundEngine through 1.7.8 lets a Subscriber reach a plugin operation without the required capability or ownership check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-59560
FundEngine subscribers can reach a privileged operation
FundEngine through 1.7.8 lets a Subscriber reach a plugin operation without the required capability or ownership check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
|
1.7.9 |
CVE6.5
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57406
FundEngine: A security weakness
FundEngine is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.7.6.
|
1.7.7 |
CVE6.5
NVDPending
|
| Aug 20, 2025 |
CVE-2025-48302
FundEngine: Filesystem traversal
FundEngine is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| May 07, 2025 |
CVE-2025-47459
FundEngine: Cross-site request forgery
FundEngine is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 11, 2024 |
CVE-2024-34758
WP Fundraising Donation and Crowdfunding Platform: A security weakness
WP Fundraising Donation and Crowdfunding Platform is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|