PT-2026-56149 · WordPress · Wpfunnels
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell versions prior to 3.12.8
Description
Unauthenticated attackers can achieve Remote Code Execution by sending unsanitized values through the
postData parameter. The plugin writes these values into a PHP-includeable .log file, which is later rendered using the include once function within wpfnl show log(). For successful exploitation, the Log Settings Enable Logs toggle must be active, and an administrator must view the polluted log file via the Log Settings View UI. The nonce required to reach the endpoint is publicly available on every funnel step page, allowing the initial injection to be performed without authentication.Recommendations
Update the plugin to version 3.12.8 or later.
Disable the Enable Logs toggle in Log Settings as a temporary mitigation measure.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpfunnels