Insecure Direct Object Reference in WP Crowdfunding Plugin by WordPress
CVE-2026-73189
6.5MEDIUM
What is CVE-2026-73189?
The WP Crowdfunding plugin for WordPress is susceptible to Insecure Direct Object References (IDOR) in versions prior to 2.2.1. This vulnerability may allow unauthorized users to access or manipulate sensitive data, potentially leading to data exposure and privacy risks. Proper input validation and permission checks are crucial to mitigate these risks and ensure secure user interactions.
Affected Version(s)
WP Crowdfunding < 2.2.1