VYPR
Medium severity4.3NVD Advisory· Published May 7, 2025· Updated Apr 23, 2026

CVE-2025-47459

CVE-2025-47459

Description

Cross-Site Request Forgery (CSRF) vulnerability in Roxnor FundEngine wp-fundraising-donation allows Cross Site Request Forgery.This issue affects FundEngine: from n/a through <= 1.7.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A Cross-Site Request Forgery (CSRF) vulnerability in FundEngine wp-fundraising-donation allows an attacker to force privileged users into performing unwanted actions without authentication.

The FundEngine plugin for WordPress (wp-fundraising-donation) versions up to 1.7.3 contain a Cross-Site Request Forgery (CSRF) vulnerability [1]. The root cause is the absence of proper CSRF protection mechanisms (such as nonce validation) on sensitive actions, enabling an attacker to craft malicious requests that are executed under the identity of a higher-privileged user [1].

Exploitation requires user interaction—the victim (a logged-in administrator or other privileged role) must click a crafted link, submit a malicious form, or visit a page designed by the attacker [1]. This does not require any authentication from the attacker, as the victim's active session is hijacked to perform the attacker's intent.

Successful exploitation could allow an attacker to force the victim to change plugin settings, create fraudulent donations, or initiate other unintended state-changing operations within the WordPress site, all under the victim's current session [1].

As of version 1.7.4 of the FundEngine plugin, the CSRF vulnerability has been patched [1]. Users are strongly advised to update to version 1.7.4 or later. For Patchstack subscribers, auto-updates can be enabled to protect vulnerable installations automatically [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.