Junglewise Threat Intelligence

CVE-2026-13080: getwpfunnels WPFunnels Local File Inclusion in logKey parameter

CVE-2026-13080 · Severity: medium · CVSS 6.6 · Published 2026-07-09

Technologies: WPFunnels. Vendors: WPFunnels.

Executive brief

WPFunnels, a WordPress plugin used to create sales funnels and checkout experiences for WooCommerce, contains a security vulnerability that could allow an administrator to execute unauthorized code on the server. By manipulating a specific setting, an attacker with high-level access can force the website to run malicious files. This could lead to a full takeover of the website, data theft, or disruption of the online store's operations.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the WPFunnels plugin for WordPress due to improper validation of the 'logKey' parameter within the settings module. Authenticated attackers with administrator-level privileges can exploit this flaw to include and execute arbitrary .php files already present on the server. While the attack requires high privileges and specific conditions (such as the ability to upload or locate a target .php file), it can lead to full remote code execution (RCE). The vulnerability is present in all versions up to and including 3.12.7; users should update to the latest patched version.

Affected products

  • getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell up to, and including, 3.12.7

Timeline

  • 2026-07-09: disclosed: CVE published by Wordfence and NVD

References

Related threats