« Volver al listado

Getwpfunnels

Getwpfunnels Wpfunnels: vulnerabilidades y CVE

Getwpfunnels Wpfunnels tiene 21 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE21
Últimos 12 meses16
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97269Media (6.5)0.19%—1 oct 2026
Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.
CVE-2026-97271Alta (7.1)0.15%—30 sept 2026
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
CVE-2026-27371Alta (7.1)0.18%—30 sept 2026
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
CVE-2026-84908Media (5.3)0.42%—9 sept 2026
The WPFunnels plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.12.13. This is due to the plugin registering the 'wpfnl_load_payment' AJAX action for both authenticated and…
CVE-2026-79632Media (5.3)0.30%—4 sept 2026
The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing…
CVE-2026-79631Media (5.3)0.34%—4 sept 2026
The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order…
CVE-2026-79630Media (5.3)0.30%—4 sept 2026
The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any…
CVE-2025-15691Media (5.3)0.18%—4 sept 2026
The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead,…
CVE-2026-84754Media (6.5)0.33%—3 sept 2026
Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
CVE-2026-15103Alta (8.8)0.56%—16 jul 2026
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This…
CVE-2026-13080Media (6.6)1.2%—9 jul 2026
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter…
CVE-2026-14345Crítica (9.8)1.4%—7 jul 2026
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter…
CVE-2026-0626Media (6.4)0.20%—4 abr 2026
The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all versions up to, and…
CVE-2025-67571Media (5.3)0.25%—9 dic 2025
Missing Authorization vulnerability in WPFunnels WPFunnels wpfunnels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPFunnels: from n/a through <= 3.6.2.
CVE-2025-12353Media (5.3)0.22%—8 nov 2025
The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including,…
CVE-2025-12000Media (6.5)0.73%—8 nov 2025
The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpfnl_delete_log() function in all versions up to, and including, 3.6.2. This makes it possible…
CVE-2025-54696Media (6.5)0.22%—14 ago 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels allows Stored XSS.This issue affects WPFunnels: from n/a through <= 3.5.26.
CVE-2025-47530Crítica (9.8)0.46%—23 may 2025
Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels wpfunnels allows Object Injection.This issue affects WPFunnels: from n/a through <= 3.5.18.
CVE-2024-10792Media (6.1)0.61%—21 nov 2024
The Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 3.5.5 due to…
CVE-2024-27965Media (4.8)0.34%—21 mar 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels.This issue affects WPFunnels: from n/a through <= 3.0.6.
CVE-2023-37977Media (6.1)0.38%—27 jul 2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFunnels Team Drag & Drop Sales Funnel Builder for WordPress – WPFunnels plugin <= 2.7.16 versions.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1059.007 JavaScript2
  3. T1189 Drive-by Compromise2
  4. T1005 Data from Local System1
  5. T1059 Command and Scripting Interpreter1
  6. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Getwpfunnels