PT-2026-81169 · WordPress · Fundengine

·

CVE-2026-76063

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FundEngine – Donation and Crowdfunding Platform plugin for WordPress versions prior to 1.8.2
Description Insufficient input sanitization and output escaping allow authenticated attackers with subscriber-level access and above to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. Attackers can inject arbitrary web scripts via the wfp featured video url parameter. These scripts execute whenever a user accesses the affected page. The issue is facilitated by a REST endpoint used to submit the video URL that has its permission callback set to return true, allowing any authenticated user to reach the vulnerable code path.
Recommendations Update the plugin to a version newer than 1.8.1. As a temporary mitigation, restrict access to the REST endpoint used for submitting the wfp featured video url parameter.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76063

Affected Products

Fundengine