Themeum WP Crowdfunding
cpe:2.3:a:themeum:wp_crowdfunding:*:*:*:*:wordpress:*:*
- <= 2.1.14
A vulnerability exists in the WP Crowdfunding plugin for WordPress, in all versions through 2.1.14. The issue arises from a missing capability check on the download_data action, which allows authenticated users with subscriber-level access and above to download all post content from a site, but only when WooCommerce is installed.
Exploitation of this vulnerability allows for unauthorized access to and downloading of a site's post content by authenticated users with subscriber-level access or higher.
Users can update to WP Crowdfunding version 2.1.15 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.