Getwpfunnels
Getwpfunnels Wpfunnels: vulnerabilidades y CVE
Getwpfunnels Wpfunnels tiene 21 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses16
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97269 | Media (6.5) | 0.19% | — | 1 oct 2026 | Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions. |
| CVE-2026-97271 | Alta (7.1) | 0.15% | — | 30 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. |
| CVE-2026-27371 | Alta (7.1) | 0.18% | — | 30 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. |
| CVE-2026-84908 | Media (5.3) | 0.42% | — | 9 sept 2026 | The WPFunnels plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.12.13. This is due to the plugin registering the 'wpfnl_load_payment' AJAX action for both authenticated and… |
| CVE-2026-79632 | Media (5.3) | 0.30% | — | 4 sept 2026 | The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing… |
| CVE-2026-79631 | Media (5.3) | 0.34% | — | 4 sept 2026 | The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order… |
| CVE-2026-79630 | Media (5.3) | 0.30% | — | 4 sept 2026 | The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any… |
| CVE-2025-15691 | Media (5.3) | 0.18% | — | 4 sept 2026 | The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead,… |
| CVE-2026-84754 | Media (6.5) | 0.33% | — | 3 sept 2026 | Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. |
| CVE-2026-15103 | Alta (8.8) | 0.56% | — | 16 jul 2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This… |
| CVE-2026-13080 | Media (6.6) | 1.2% | — | 9 jul 2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter… |
| CVE-2026-14345 | Crítica (9.8) | 1.4% | — | 7 jul 2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter… |
| CVE-2026-0626 | Media (6.4) | 0.20% | — | 4 abr 2026 | The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all versions up to, and… |
| CVE-2025-67571 | Media (5.3) | 0.25% | — | 9 dic 2025 | Missing Authorization vulnerability in WPFunnels WPFunnels wpfunnels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPFunnels: from n/a through <= 3.6.2. |
| CVE-2025-12353 | Media (5.3) | 0.22% | — | 8 nov 2025 | The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including,… |
| CVE-2025-12000 | Media (6.5) | 0.73% | — | 8 nov 2025 | The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpfnl_delete_log() function in all versions up to, and including, 3.6.2. This makes it possible… |
| CVE-2025-54696 | Media (6.5) | 0.22% | — | 14 ago 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels allows Stored XSS.This issue affects WPFunnels: from n/a through <= 3.5.26. |
| CVE-2025-47530 | Crítica (9.8) | 0.46% | — | 23 may 2025 | Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels wpfunnels allows Object Injection.This issue affects WPFunnels: from n/a through <= 3.5.18. |
| CVE-2024-10792 | Media (6.1) | 0.61% | — | 21 nov 2024 | The Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 3.5.5 due to… |
| CVE-2024-27965 | Media (4.8) | 0.34% | — | 21 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels.This issue affects WPFunnels: from n/a through <= 3.0.6. |
| CVE-2023-37977 | Media (6.1) | 0.38% | — | 27 jul 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFunnels Team Drag & Drop Sales Funnel Builder for WordPress – WPFunnels plugin <= 2.7.16 versions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.