Review
Crowdfundly
CVE published 2026-10-11
CVE-2026-85126
The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover. This vulnerability allows low-privileged users to potentially escalate privileges and take over a WordPress site. Defenders should assess [truncated]