« Volver al listado

Wpmet

Wpmet Fundengine: vulnerabilidades y CVE

Wpmet Fundengine tiene 8 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses6
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-76063Media (6.4)0.35%—25 ago 2026
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to…
CVE-2026-75930Media (4.3)0.37%—25 ago 2026
The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is…
CVE-2026-73993Crítica (9.8)0.56%—20 ago 2026
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-32470Crítica (9.8)0.56%—18 ago 2026
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-59560Media (6.5)0.37%—27 jul 2026
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
CVE-2026-57406Media (6.5)0.33%—13 jul 2026
Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6.
CVE-2024-6698Alta (8.8)0.43%—1 ago 2024
The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta…
CVE-2022-0788Crítica (9.8)7.9%—8 jun 2022
The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1190 Exploit Public-Facing Application2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Wpmet