CVE-2026-85126 PUBLISHED

Crowdfundly <= 2.2.2 - Crowdfundly Manager+ Privilege Escalation

Assigner: WPScan
Reserved: 03.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover.

Product Status

Vendor Unknown
Product Crowdfundly
Versions Default: unknown
  • affected from 0 to 2.2.2 (incl.)

Credits

  • Enrico Marcolini - Claudio Marchesini - Dottor Marc finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE