FundPress <= 2.0.8 - Missing Authorization to Unauthenticated Arbitrary Donation Status Modification via donate_action_status AJAX Handler
medium
The FundPress – WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and including 2.0.8. This is due to missing authorization and nonce verification in the donate_action_status() AJAX handler, which is registered to be accessible to unauthenticated users via wp_ajax_nopriv. T...
- CVSS:
- 5.3
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- May 1, 2026
CVE-2026-4650 on NVD →
FundPress – WordPress Donation Plugin [fundpress] < 2.0.7
unknown
[en] Deserialization of Untrusted Data vulnerability in ThimPress FundPress allows Object Injection. This issue affects FundPress: from n/a through 2.0.6.
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Jan 27, 2025
CVE-2025-24601 on NVD →
FundPress <= 2.0.6 - Unauthenticated PHP Object Injection
high
The FundPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an...
- CVSS:
- 8.1
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.7
- Disclosed:
- Jan 20, 2025
CVE-2025-24601 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database