roxnor Vulnerabilities and Affected Products
Vulnerabilities associated with FundEngine – Donation and Crowdfunding Platform.
Products
Clear product- MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor23 vulnerabilities
- ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor19 vulnerabilities
- Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers5 vulnerabilities
- EmailKit – Email Customizer for WooCommerce & WP4 vulnerabilities
- FundEngine4 vulnerabilities
- Wp Social Login and Register Social Counter4 vulnerabilities
- GetGenie3 vulnerabilities
- GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools3 vulnerabilities
- Metform3 vulnerabilities
- ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution3 vulnerabilities
- Wp Ultimate Review3 vulnerabilities
- ElementsKit Elementor addons Lite2 vulnerabilities
- PopupKit2 vulnerabilities
- EmailKit1 vulnerability
- FundEngine – Donation and Crowdfunding Platform1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-6698HIGH | FundEngine – Donation and Crowdfunding Platform <= 1.7.0 - Authenticated (Subscriber+) Privilege EscalationThe FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta which can be leveraged to update their capabilities to gain administrator access. CWE-862Aug 1, 2024 | CVSS8.8v3.1 | EPSS0.431% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |