Unrated severityNVD Advisory· Published Oct 11, 2026
CVE-2026-85126
CVE-2026-85126
Description
The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.2.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.