Sceawere
Vulnerability Detail
CVE-2026-85126UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Privilege Escalation in Crowdfundly
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Crowdfundly
- Attack Type
- CWE-269 Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-11T07:17:26.113Z",
"pubdate": "2026-10-11T07:17:26.113Z",
"executiveSummary": "The Crowdfundly WordPress plugin, specifically versions up to and including 2.2.2, contains a critical security vulnerability involving improper authorization for AJAX actions. This flaw allows authenticated users with low-privileged roles defined by the plugin to perform unauthorized administrative operations.\nBy manipulating specific AJAX requests, an attacker can modify user role assignments or grant arbitrary WordPress capabilities to their own account. This results in a full site takeover, as the attacker effectively elevates their privileges to that of an administrator. The vulnerability represents a high risk to the confidentiality, integrity, and availability of the affected WordPress instance. Successful exploitation requires an attacker to possess a low-level account on the target site but does not necessitate complex social engineering or external interaction beyond invoking the vulnerable AJAX hooks.",
"technicalDetails": "The root cause of this vulnerability lies in the absence of robust capability checks within the plugin's AJAX handler functions. In WordPress, AJAX actions registered via 'wp_ajax_' and 'wp_ajax_nopriv_' hooks must explicitly verify that the requesting user possesses the necessary permissions—typically using 'current_user_can()'—to execute the requested functionality. Crowdfundly failed to implement these requisite authorization checks for certain internal management actions.\nThe attack flow begins with an attacker possessing a low-privileged account, such as a subscriber or a custom role created by the Crowdfundly plugin. Because the plugin does not validate the security context of the incoming request, an attacker can craft a POST request targeting the 'admin-ajax.php' endpoint with the specific 'action' parameter associated with the vulnerable functionality.\nUpon receiving the request, the server invokes the unprotected function. The attacker can supply parameters within the request body that explicitly define user ID and target role identifiers. Because the backend logic lacks an authentication handshake for the privilege modification process, the plugin proceeds to execute the database update. Specifically, the vulnerable code interacts with the 'wp_update_user' or 'WP_User::set_role' functions without first validating the current user's session or their capability to perform administrative modifications.\nBy setting their own user ID as the target, the attacker overwrites their existing role record in the 'wp_usermeta' table with 'administrator'. Once the database reflects this change, the attacker gains full access to the WordPress administrative dashboard, permitting them to install malicious plugins, create backdoors, modify site content, or perform arbitrary code execution via file uploads.\nThe affected versions are all iterations of Crowdfundly up to 2.2.2. This vulnerability is inherently exploitable because the AJAX handlers are globally accessible once a session is established, bypassing the architectural security model of the WordPress core. The lack of nonce verification further facilitates this, as an attacker does not need to possess a valid CSRF token to complete the request chain."
}