PatchSiren

Crowdfundly CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Crowdfundly CVE published 2026-10-11

CVE-2026-85126

The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover. This vulnerability allows low-privileged users to potentially escalate privileges and take over a WordPress site. Defenders should assess [truncated]