Input validation vulnerability in FundEngine – Donation and Crowdfunding Platform 1.7.4

A plugin called FundEngine used in WordPress has a security issue in versions up to 1.7.4. This means that people who are logged in and have certain levels of access can make the plugin include and use files on the server. This can lead to them being able to run any code they want. It can also be used to get around security measures, get private information, or run code even if the file is supposed to be safe.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.