Stored Cross-Site Scripting in WP Crowdfunding Plugin for WordPress
CVE-2026-19945
6.4MEDIUM
What is CVE-2026-19945?
The WP Crowdfunding plugin for WordPress has a vulnerability that allows attackers with subscriber-level access or higher to exploit stored cross-site scripting via the 'first_name' parameter. The issue stems from inadequate input sanitization and output escaping, enabling the injection of arbitrary web scripts. When an administrator views any user's profile using the ?show_user_id= parameter, the attacker's stored script can execute within the admin's browser session, posing a significant risk for cross-privilege script execution.
Affected Version(s)
WP Crowdfunding 0 <= 2.2.1