Junglewise Threat Intelligence

CVE-2026-39450: FunnelKit Automations broken authentication in WordPress plugin

CVE-2026-39450 · Severity: high · CVSS 7.1 · Published 2026-06-15

Vendors: FunnelKit.

Executive brief

FunnelKit Automations, a marketing automation plugin for WordPress, contains a security flaw that allows users with low-level 'Subscriber' accounts to bypass authentication. This could allow an attacker to perform actions intended for administrators, potentially leading to a full takeover of the website. Organizations using this plugin should update to version 3.8.0 immediately to prevent unauthorized access.

Technical details

FunnelKit Automations (formerly Autonami) versions 3.7.3 and earlier are vulnerable to an authentication bypass (CWE-288). The flaw allows an authenticated user with low-level 'Subscriber' privileges to bypass intended access controls via an alternate path or channel. By exploiting this broken authentication, a malicious actor can execute functions typically reserved for higher-privileged users, which may lead to administrative access or significant service disruption. The vulnerability is remediated in version 3.8.0.

Affected products

  • FunnelKit FunnelKit Automations <= 3.7.3

Timeline

  • 2026-03-17: other: Reported by Jakub Herman
  • 2026-04-22: advisory: Initial Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-04-22: patched: Version 3.8.0 released to address the issue

References