Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WP Crowdfunding — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in WP Crowdfunding, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the web application WP Crowdfunding, classified under the web application software category and tagged with the "WP Crowdfunding" identifier. The collection includes reported defects such as cross-site scripting, SQL injection, and privilege escalation issues, spanning releases from the plugin's initial public launch through its latest maintained version. Readers can use this page to track the vendor’s published security advisories, analyze the recurrence of specific weakness classes, and review the complete vulnerability history for this product.

Vendor: Themeum

CVE ID Title CVSS Severity Published
CVE-2026-19945 WP Crowdfunding <= 2.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'first_name' Parameter CWE-79 6.4 Medium 2026-09-09
CVE-2026-19944 WP Crowdfunding <= 2.2.1 - Authenticated (Shop Manager+) SQL Injection via 'wpneo_reward' Post Meta CWE-89 4.9 Medium 2026-09-09
CVE-2026-14859 WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Creation via Missing Authorization - - 2026-08-12
CVE-2026-14858 WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR - - 2026-08-12
CVE-2026-14857 WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Update Modification via IDOR - - 2026-08-12
CVE-2025-31892 WordPress WP Crowdfunding plugin <= 2.1.15 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-04-01
CVE-2025-1508 WP Crowdfunding <= 2.1.14 - Missing Authorization to Authenticated (Subscriber+) Post Content Download CWE-862 5.3 Medium 2025-03-12
CVE-2023-41870 WordPress WP Crowdfunding plugin <= 2.1.5 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-12-13
CVE-2024-11910 WP Crowdfunding <= 2.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-12-13
CVE-2024-11911 WP Crowdfunding <= 2.1.12 - Missing Authorization to Authenticated (Subscriber+) WooCommerce Installation CWE-862 4.3 Medium 2024-12-13
CVE-2024-43937 WordPress WP Crowdfunding plugin <= 2.1.10 - Settings Change vulnerability CWE-862 6.4 Medium 2024-11-01
CVE-2024-10117 WP Crowdfunding <= 2.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpcf_donate Shortcode CWE-79 6.4 Medium 2024-10-26
CVE-2023-6163 WP Crowdfunding < 2.1.10 - Admin+ Stored XSS 4.8 - 2024-01-15
CVE-2023-6161 WP Crowdfunding < 2.1.9 - Reflected XSS 6.1AI Medium AI 2024-01-08
CVE-2023-50859 WordPress WP Crowdfunding Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS) CWE-79 6.5 Medium 2023-12-28
CVE-2023-5757 WP Crowdfunding < 2.1.8 - Admin+ Stored XSS 4.8AI Medium AI 2023-12-11
CVE-2023-47532 WordPress WP Crowdfunding Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.8 Medium 2023-11-14

All 17 known CVE vulnerabilities affecting WP Crowdfunding with full Chinese analysis, references, and POCs where available.