🔐 CVE Alert

CVE-2024-6698

HIGH 8.8

FundEngine – Donation and Crowdfunding Platform <= 1.7.0 - Authenticated (Subscriber+) Privilege Escalation

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta which can be leveraged to update their capabilities to gain administrator access.

CWE CWE-862
Vendor roxnor
Product fundengine – donation and crowdfunding platform
Published Aug 1, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for roxnor fundengine – donation and crowdfunding platform

Be the first to know when new high vulnerabilities affecting roxnor fundengine – donation and crowdfunding platform are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

roxnor / FundEngine – Donation and Crowdfunding Platform
0 ≤ 1.7.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/2ec6cf42-291b-452d-ad14-80ae1cd5ec5c?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3128099%40wp-fundraising-donation%2Ftrunk&old=3072093%40wp-fundraising-donation%2Ftrunk&sfp_email=&sfph_mail=

Credits

Thanh Nam Tran