CVE-2026-14858: Unknown Wp Crowdfunding
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.
Affected products
- Unknown Wp Crowdfunding: before 2.2.1 (fixed in 2.2.1)
Published 2026-08-12. Last modified 2026-08-26.