Executive brief
WPFunnels, a WordPress plugin used to create sales funnels and checkout processes for WooCommerce, contains a security flaw that allows certain authorized users to gain full administrative control over the website. By exploiting this vulnerability, a user with limited 'Funnel Manager' permissions can rewrite site settings to grant themselves or others unrestricted access. This could lead to a total site takeover, data theft, or complete service disruption.
Technical details
The vulnerability exists in the `update_settings()` REST callback due to a lack of validation on the `group_id` path parameter. The callback fails to check the parameter against an allowlist before passing it to `update_option()`, and the associated route uses a loose regex (`[\w-]+`) that matches the core WordPress `wp_user_roles` option. An authenticated attacker with the `wpf_manage_funnels` capability (typically the 'Funnel Manager' role) can send a crafted request to overwrite the site's role definitions. By injecting arbitrary capabilities into a role, the attacker can elevate their privileges to Administrator. A patch was released in version 3.12.9.
Affected products
- getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell up to, and including, 3.12.8
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory
References
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.8/includes/core/rest-api/Controllers/class-settings-controller.php
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.8/includes/core/rest-api/Controllers/class-settings-controller.php
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.8/includes/core/rest-api/Controllers/class-settings-controller.php
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.8/includes/utils/class-wpfnl-functions.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3607181%40wpfunnels&new=3607181%40wpfunnels
- https://www.wordfence.com/threat-intel/vulnerabilities/id/76ad6d21-f277-496f-aa6b-f9d5cb8a3801?source=cve