Executive brief
The WPFunnels plugin for WordPress, which is used to create sales funnels and lead generation forms, contains a security vulnerability. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The WPFunnels plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'button_icon' parameter within the 'wpf_optin_form' shortcode. This vulnerability exists in all versions up to and including 3.7.9. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting malicious JavaScript into a page via the shortcode. Because the script is stored on the server, it executes in the context of any user's browser session when they navigate to the affected page. A patch appears to have been addressed in changeset 3439366.
Affected products
- getwpfunnels WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales <= 3.7.9
Timeline
- 2026-04-04: disclosed
- 2026-04-04: advisory