PT-2026-56149 · WordPress · Wpfunnels

·

CVE-2026-14345

·

Published

2026-07-07

·

Updated

2026-07-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell versions prior to 3.12.8
Description Unauthenticated attackers can achieve Remote Code Execution by sending unsanitized values through the postData parameter. The plugin writes these values into a PHP-includeable .log file, which is later rendered using the include once function within wpfnl show log(). For successful exploitation, the Log Settings Enable Logs toggle must be active, and an administrator must view the polluted log file via the Log Settings View UI. The nonce required to reach the endpoint is publicly available on every funnel step page, allowing the initial injection to be performed without authentication.
Recommendations Update the plugin to version 3.12.8 or later. Disable the Enable Logs toggle in Log Settings as a temporary mitigation measure.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14345

Affected Products

Wpfunnels