IgnitionDeck Crowdfunding Platform [ignitiondeck] <= 2.0.10 (unfixed)
unknown
[en] Missing Authorization vulnerability in ignitionwp IgnitionDeck ignitiondeck allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IgnitionDeck: from n/a through <= 2.0.10.
- Affected:
- up to 2.0.10
- Fix:
- No patched version reported
- Disclosed:
- Oct 27, 2025
CVE-2025-62918 on NVD →
IgnitionDeck <= 2.0.10 - Missing Authorization
medium
The IgnitionDeck plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.0.10
- Fix:
- No patched version reported
- Disclosed:
- Oct 4, 2025
CVE-2025-62918 on NVD →
IgnitionDeck Crowdfunding Platform [ignitiondeck] < 1.10.0
unknown
[en] The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability checks on various functions called via AJAX actions in the ~/classes/class-idf-wizard.php file. This makes it possible for authenticated atta...
- Affected:
- up to 1.10.0
- Fixed in:
- 1.10.0
- Disclosed:
- Jul 27, 2024
CVE-2024-4410 on NVD →
IgnitionDeck Crowdfunding Platform <= 1.9.8 - Missing Authorization
medium
The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability checks on various functions called via AJAX actions in the ~/classes/class-idf-wizard.php file. This makes it possible for authenticated attackers...
- CVSS:
- 5.4
- Affected:
- up to 1.9.8
- Fixed in:
- 1.10.0
- Disclosed:
- Jul 26, 2024
CVE-2024-4410 on NVD →
IgnitionDeck Crowdfunding Platform <= 1.1.6 - Missing Authorization
high
The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.1.6. This is due to missing capability checks on various functions called via AJAX actions. This makes it possible for unauthenticated attackers to execute various AJAX actions including...
- CVSS:
- 7.3
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Mar 6, 2015
IgnitionDeck Crowdfunding Platform [ignitiondeck] < 1.1.7
unknown
The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.1.6. This is due to missing capability checks on various functions called via AJAX actions. This makes it possible for unauthenticated attackers to execute various AJAX actions including...
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Mar 6, 2015
IgnitionDeck Crowdfunding Platform [ignitiondeck] < 1.2
unknown
This plugin is prone to a purchase form cross site scripting vulnerability.
Upgrade this plugin.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Aug 1, 2014
IgnitionDeck Crowdfunding Platform [ignitiondeck] < 1.2
unknown
The IgnitionDeck Crowdfunding & Commerce WordPress plugin was affected by a Purchase Form Unspecified XSS security vulnerability.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database