CVE-2026-14859: Unknown Wp Crowdfunding

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX actions, allowing any authenticated users such as Subscribers to create crowdfunding campaign posts despite not being granted that permission.

Affected products

  • Unknown Wp Crowdfunding: before 2.2.1 (fixed in 2.2.1)

Published 2026-08-12. Last modified 2026-08-26.