Wpmet
Wpmet Fundengine: vulnerabilidades y CVE
Wpmet Fundengine tiene 8 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses6
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76063 | Media (6.4) | 0.35% | — | 25 ago 2026 | The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to… |
| CVE-2026-75930 | Media (4.3) | 0.37% | — | 25 ago 2026 | The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is… |
| CVE-2026-73993 | Crítica (9.8) | 0.56% | — | 20 ago 2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. |
| CVE-2026-32470 | Crítica (9.8) | 0.56% | — | 18 ago 2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. |
| CVE-2026-59560 | Media (6.5) | 0.37% | — | 27 jul 2026 | Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. |
| CVE-2026-57406 | Media (6.5) | 0.33% | — | 13 jul 2026 | Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6. |
| CVE-2024-6698 | Alta (8.8) | 0.43% | — | 1 ago 2024 | The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta… |
| CVE-2022-0788 | Crítica (9.8) | 7.9% | — | 8 jun 2022 | The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Wpmet
Metform Elementor Contact Form Builder · 23Elements KIT Elementor Addons · 14Elementskit · 11WP Ultimate Review · 10Elementskit Elementor Addons · 10Gutenkit · 7WP Social Login AND Register Social Counter · 5Elementskit Lite · 2Elementskit Elementor Addons Lite · 2Shopengine · 1Metform · 1WP Fundraising Donation AND Crowdfunding Platform · 1