VYPR

Crowdfundly

by WordPress

CVEs (1)

  • CVE-2026-85126Oct 11, 2026
    risk 0.00cvss —epss —

    The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover.