Feed/CVE-2026-14858
CVE-2026-14858

CVE-2026-14858

Published Aug 12, 2026·Updated Aug 12, 2026

NVD Description

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowing any authenticated users such as Subscribers to read the personal data of any WooCommerce order and enumerate every order in the store.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free