WordPress 插件 FundEngine – Donation and Crowdfunding Platform 在所有不超过 1.8.1 的版本中存在授权绕过漏洞。该漏洞是由于插件未正确验证用户是否有权执行特定操作所致。这使得具有订阅者级别及以上权限的已认证攻击者能够修改任意文章和页面——包括覆盖标题和内容,并通过提供攻击者控制的 post_author 整数值来接管页面所有权,从而绕过 wp_kses_post 的 sanitization(安全净化)机制。 处理程序所需的 wp_rest nonce(
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| roxnor | FundEngine – Donation and Crowdfunding Platform | 0 ~ 1.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75971 | 7.2 HIGH | ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Pr |
| CVE-2026-76063 | 6.4 MEDIUM | FundEngine <= 1.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_fea |
| CVE-2026-18100 | 6.4 MEDIUM | MetForm <= 4.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_i |
No comments yet