WordPress · Wp Crowdfunding · CVE-2026-14859
**Name of the Vulnerable Software and Affected Versions**
WP Crowdfunding WordPress plugin versions prior to 2.2.1
**Description**
An issue exists where the plugin fails to verify the `campaign-submission` capability within an AJAX action. This allows authenticated users with low privileges, such as Subscribers, to create crowdfunding campaign posts without the required permissions.
**Recommendations**
Update the plugin to version 2.2.1 or later.