top of page
perceptive_background_267k.jpg

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up t…

Published:

6 juli 2026 om 22:00:00

Alert date:

7 juli 2026 om 14:06:37

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

The WPFunnels plugin for WordPress (versions up to and including 3.12.7) is vulnerable to Remote Code Execution via the 'postData' parameter. Attackers can inject unsanitized PHP code into a .log file, which is then executed via include_once when an administrator views the log file through the plugin's Log Settings UI. While full exploitation requires logging to be enabled and an admin to open the polluted log, the injection step itself is fully unauthenticated because the required nonce is publicly emitted on every funnel step page. This vulnerability poses a critical risk as it can lead to complete server compromise. A patch is available in version 3.12.8 of the plugin.

Technical details

Mitigation steps:

Affected products:

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell (WordPress plugin
versions up to 3.12.7)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page