Junglewise Threat Intelligence

CVE-2026-15103: WPFunnels privilege escalation via arbitrary option update

CVE-2026-15103 · Severity: high · CVSS 8.8 · Published 2026-07-16

Technologies: WPFunnels. Vendors: WPFunnels.

Executive brief

WPFunnels, a WordPress plugin used to create sales funnels and checkout processes for WooCommerce, contains a security flaw that allows certain authorized users to gain full administrative control over the website. By exploiting this vulnerability, a user with limited 'Funnel Manager' permissions can rewrite site settings to grant themselves or others unrestricted access. This could lead to a total site takeover, data theft, or complete service disruption.

Technical details

The vulnerability exists in the `update_settings()` REST callback due to a lack of validation on the `group_id` path parameter. The callback fails to check the parameter against an allowlist before passing it to `update_option()`, and the associated route uses a loose regex (`[\w-]+`) that matches the core WordPress `wp_user_roles` option. An authenticated attacker with the `wpf_manage_funnels` capability (typically the 'Funnel Manager' role) can send a crafted request to overwrite the site's role definitions. By injecting arbitrary capabilities into a role, the attacker can elevate their privileges to Administrator. A patch was released in version 3.12.9.

Affected products

  • getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell up to, and including, 3.12.8

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats