Funnelkit
Funnelkit Automations: vulnerabilidades y CVE
Funnelkit Automations tiene 10 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-39450 | Alta (7.1) | 0.40% | — | 15 jun 2026 | Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions. |
| CVE-2025-12469 | Media (4.3) | 0.24% | — | 5 nov 2025 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.4.1. This is due to the… |
| CVE-2025-12468 | Media (5.3) | 0.35% | — | 5 nov 2025 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.4.1 via the… |
| CVE-2025-1562 | Crítica (9.8) | 3.3% | — | 18 jun 2025 | The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check… |
| CVE-2025-49868 | Media (4.7) | 0.23% | — | 17 jun 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Aman FunnelKit Automations wp-marketing-automations allows Phishing.This issue affects FunnelKit Automations: from n/a through <= 3.6.0. |
| CVE-2025-30795 | Media (4.7) | 0.39% | — | 27 mar 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Aman FunnelKit Automations wp-marketing-automations allows Phishing.This issue affects FunnelKit Automations: from n/a through <= 3.5.1. |
| CVE-2024-9186 | Alta (8.6) | 2.3% | — | 14 nov 2024 | The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL… |
| CVE-2024-47328 | Alta (7.2) | 0.49% | — | 21 oct 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman FunnelKit Automations wp-marketing-automations allows SQL Injection.This issue affects FunnelKit Automations:… |
| CVE-2023-50857 | Alta (7.2) | 0.53% | — | 28 dic 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit.This… |
| CVE-2022-2389 | Media (4.3) | 0.36% | — | 22 ago 2022 | The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Funnelkit
Funnel Builder · 13Slingblocks · 3Funnelkit · 3Funnelkit Checkout · 3Funnel Builder FOR Woocommerce Checkout · 2Funnel Builder PRO · 2Recover Woocommerce Cart Abandonment · 1Automations Email Marketing Automation AND CRM FOR Wordpress AND Woocommerce · 1Funnelkit Funnel Builder FOR Woocommerce Checkout · 1Payment Gateway FOR Stripe Woocommerce · 1