CVE-2025-1508
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 12, 2025
Updated: Mar 20, 2025
CWE ID 862
Summary
CVE-2025-1508 is a vulnerability affecting the WP Crowdfunding plugin for WordPress. The issue lies in the plugin's failure to implement proper capability checks for the 'download_data' action, which exists in all versions up to 2.1.13. Consequently, authenticated attackers with subscriber-level access and higher can exploit this flaw to gain unauthorized access to a site's post content, posing a significant risk when WooCommerce is installed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Themeum Wp Crowdfunding
Affected Vendors
- THEMEUM