PT-2026-60424 · WordPress · Funnelkit
CVE-2026-12979
·
Published
2026-07-16
·
Updated
2026-07-16
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
FunnelKit WordPress plugin versions prior to 3.15.0.6
Description
An issue exists during the template-import operation where the software fails to validate a user-supplied path before deleting a file. This allows users with administrator privileges to perform path traversal—a technique used to access files and directories that are stored outside the web root folder—to delete arbitrary
.json files outside the intended directory. This action can lead to a denial of service by disabling the plugin.Recommendations
Update FunnelKit WordPress plugin to version 3.15.0.6 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Funnelkit