← WordPress Vulnerabilities
WordPress security by component

FundEngine

FundEngine is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: wp-fundraising-donation

CVE-2026-59560: FundEngine subscribers can reach a privileged operation

FundEngine through 1.7.8 lets a Subscriber reach a plugin operation without the required capability or ownership check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.

PublishedJul 27, 2026
Known safe version1.7.9
Safe version
Jul 27, 2026 CVE-2026-59560
FundEngine subscribers can reach a privileged operation
FundEngine through 1.7.8 lets a Subscriber reach a plugin operation without the required capability or ownership check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
1.7.9
CVE6.5
NVDPending
Jul 13, 2026 CVE-2026-57406
FundEngine: A security weakness
FundEngine is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.7.6.
1.7.7
CVE6.5
NVDPending
Aug 20, 2025 CVE-2025-48302
FundEngine: Filesystem traversal
FundEngine is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
May 07, 2025 CVE-2025-47459
FundEngine: Cross-site request forgery
FundEngine is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Jun 11, 2024 CVE-2024-34758
WP Fundraising Donation and Crowdfunding Platform: A security weakness
WP Fundraising Donation and Crowdfunding Platform is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending