Medium 6.5
2025-04-01< 2.1.16
CVE-2025-31892
Minimum safe version
2.1.16
Update to 2.1.16 or later to address 14 fixable vulnerabilities
CVE-2025-31892
WP Crowdfunding <= 2.1.14 - Missing Authorization to Authenticated (Subscriber+) Post Content Download
CVE-2024-11910
CVE-2024-11911
CVE-2024-10117
CVE-2024-43937
CVE-2023-6163
CVE-2023-6161
WP Crowdfunding < 2.1.6 - Cross-Site Request Forgery
WordPress WP Crowdfunding Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)
WordPress WP Crowdfunding Plugin < 2.1.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-47532
WP Crowdfunding <= 2.1.5 - Cross-Site Request Forgery
CVE-2023-41870