


Perceptive Security
SOC/SIEM Consultancy

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up t…
Published:
6 juli 2026 om 22:00:00
Alert date:
7 juli 2026 om 14:06:37
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
The WPFunnels plugin for WordPress (versions up to and including 3.12.7) is vulnerable to Remote Code Execution via the 'postData' parameter. Attackers can inject unsanitized PHP code into a .log file, which is then executed via include_once when an administrator views the log file through the plugin's Log Settings UI. While full exploitation requires logging to be enabled and an admin to open the polluted log, the injection step itself is fully unauthenticated because the required nonce is publicly emitted on every funnel step page. This vulnerability poses a critical risk as it can lead to complete server compromise. A patch is available in version 3.12.8 of the plugin.
Technical details
Mitigation steps:
Affected products:
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell (WordPress plugin
versions up to 3.12.7)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14345
https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/admin/modules/settings/class-wpfnl-settings.php#L709
https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/includes/core/classes/class-wpfnl-ajax-handler.php#L39
https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/includes/core/classes/class-wpfnl-ajax-handler.php#L523
https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/public/class-wpfnl-public.php#L1185
https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/admin/modules/settings/class-wpfnl-settings.php#L709
https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/includes/core/classes/class-wpfnl-ajax-handler.php#L39
https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/includes/core/classes/class-wpfnl-ajax-handler.php#L523
https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/public/class-wpfnl-public.php#L1185
https://plugins.trac.wordpress.org/changeset/3597260/wpfunnels/trunk/admin/modules/settings/class-wpfnl-settings.php
https://plugins.trac.wordpress.org/changeset?old_path=%2Fwpfunnels/tags/3.12.7&new_path=%2Fwpfunnels/tags/3.12.8
https://www.wordfence.com/threat-intel/vulnerabilities/id/5d84d749-0ab5-49dd-8e4f-45681f197742?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
