Summary
CVE-2026-73993 is an unauthenticated PHP Object Injection (deserialization of untrusted data) vulnerability affecting the Roxnor FundEngine WordPress plugin (package wp-fundraising-donation), used to build donation and crowdfunding pages. The flaw affects all versions up to and including 1.7.9 and carries a CVSS v3.1 score of 9.8 (Critical), as it can be triggered remotely over the network without authentication or user interaction.
Technical details
- Root cause: the plugin deserializes untrusted, attacker-controlled input using PHP’s native unserialization functionality (CWE-502), rather than safe data formats.
- Trigger conditions: an attacker submits crafted serialized data to a plugin endpoint/parameter that is passed into PHP’s deserialization routine; no login or interaction from a victim is required.
- Attack vector: network-based (AV:N), low attack complexity, no privileges required, no user interaction required.
- Impact: successful object injection can lead to secondary impacts such as arbitrary object instantiation and, depending on available "magic methods"/gadget chains in the WordPress/plugin environment, may result in remote code execution, data manipulation, or denial of service, consistent with the CVSS impact ratings of High confidentiality, integrity, and availability.
Affected software
- Roxnor FundEngine – Donation and Crowdfunding Platform (WordPress plugin, package
wp-fundraising-donation): versions up to and including 1.7.9 - Fixed in version 1.8.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Update the FundEngine plugin (
wp-fundraising-donation) to version 1.8.0 or later, where the deserialization issue is fixed. - If immediate patching is not possible:
- Restrict or disable public access to the plugin’s donation/form submission endpoints until patched.
- Deploy a web application firewall (WAF) rule to detect and block PHP serialized-object payloads in incoming requests to the plugin.
- Monitor web server and application logs for anomalous POST requests containing serialized PHP object strings (e.g., beginning with
O:ora:). - Take regular backups and review site integrity for signs of compromise if the plugin has been internet-exposed prior to patching.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/wp-content/plugins/wp-fundraising-donation/

