Themeum Wp Crowdfunding vulnerabilities

12 known vulnerabilities affecting themeum/wp_crowdfunding.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM10UNKNOWN1

Vulnerabilities

Page 1 of 1
CVE-2025-31892UNKNOWN≤ 2.1.152025-04-01
CVE-2025-31892 CWE-79 CVE-2025-31892: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding wp-crowdfunding allows Stored XSS.This issue affects WP Crowdfunding: from n/a through <= 2.1.15.
cvelistv5nvd
CVE-2025-1508MEDIUMCVSS 5.3≤ 2.1.132025-03-12
CVE-2025-1508 [MEDIUM] CWE-862 CVE-2025-1508: The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missi The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all versions up to, and including, 2.1.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to download all of a site's post content when WooCommerce is instal
cvelistv5nvd
CVE-2023-41870HIGHCVSS 8.8fixed in 2.1.6≥ n/a, ≤ 2.1.52024-12-13
CVE-2023-41870 [MEDIUM] CWE-862 CVE-2023-41870: Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configu Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.5.
cvelistv5nvd
CVE-2024-11910MEDIUMCVSS 5.4fixed in 2.1.13≤ 2.1.152024-12-13
CVE-2024-11910 [MEDIUM] CWE-79 CVE-2024-11910: The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-cro The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search block in all versions up to, and including, 2.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts
cvelistv5nvd
CVE-2024-11911MEDIUMCVSS 4.3fixed in 2.1.13≤ 2.1.122024-12-13
CVE-2024-11911 [MEDIUM] CWE-862 CVE-2024-11911: The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all versions up to, and including, 2.1.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install WooCommerce. This has a li
cvelistv5nvd
CVE-2024-43937MEDIUMCVSS 4.3fixed in 2.1.11≥ n/a, ≤ 2.1.102024-11-01
CVE-2024-43937 [MEDIUM] CWE-862 CVE-2024-43937: Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configu Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.10.
cvelistv5nvd
CVE-2024-10117MEDIUMCVSS 5.4fixed in 2.1.12≤ 2.1.112024-10-26
CVE-2024-10117 [MEDIUM] CWE-79 CVE-2024-10117: The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate shortcode in all versions up to, and including, 2.1.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, t
cvelistv5nvd
CVE-2023-6163MEDIUMCVSS 4.8fixed in 2.1.102024-01-15
CVE-2023-6163 [MEDIUM] CWE-79 CVE-2023-6163: The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
nvd
CVE-2023-6161MEDIUMCVSS 6.1fixed in 2.1.92024-01-08
CVE-2023-6161 [MEDIUM] CWE-79 CVE-2023-6161: The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before ou The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
nvd
CVE-2023-50859MEDIUMCVSS 5.4≤ 2.1.6≥ n/a, ≤ 2.1.62023-12-28
CVE-2023-50859 [MEDIUM] CWE-79 CVE-2023-50859: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding allows Stored XSS.This issue affects WP Crowdfunding: from n/a through 2.1.6.
cvelistv5nvd
CVE-2023-5757MEDIUMCVSS 4.8fixed in 2.1.82023-12-11
CVE-2023-5757 [MEDIUM] CWE-79 CVE-2023-5757: The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
nvd
CVE-2023-47532MEDIUMCVSS 6.1≤ 2.1.6≥ n/a, ≤ 2.1.62023-11-14
CVE-2023-47532 [MEDIUM] CWE-79 CVE-2023-47532: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themeum WP Crowdfunding plugin <= 2.1. Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themeum WP Crowdfunding plugin <= 2.1.6 versions.
cvelistv5nvd