PT-2026-81169 · WordPress · Fundengine
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FundEngine – Donation and Crowdfunding Platform plugin for WordPress versions prior to 1.8.2
Description
Insufficient input sanitization and output escaping allow authenticated attackers with subscriber-level access and above to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. Attackers can inject arbitrary web scripts via the
wfp featured video url parameter. These scripts execute whenever a user accesses the affected page. The issue is facilitated by a REST endpoint used to submit the video URL that has its permission callback set to return true, allowing any authenticated user to reach the vulnerable code path.Recommendations
Update the plugin to a version newer than 1.8.1.
As a temporary mitigation, restrict access to the REST endpoint used for submitting the
wfp featured video url parameter.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fundengine