Junglewise Threat Intelligence

CVE-2026-49778: WPFunnels WPFunnels Pro unauthenticated XSS

CVE-2026-49778 · Severity: high · CVSS 7.1 · Published 2026-06-17

Vendors: WPFunnels.

Executive brief

WPFunnels Pro, a WordPress plugin used for creating sales funnels and landing pages, contains a security flaw that allows unauthenticated attackers to execute malicious scripts. By tricking a site visitor or administrator into clicking a specific link, an attacker could steal session information, redirect users to malicious websites, or deface the site. This could lead to unauthorized access to the website's management interface or the compromise of customer data.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in WPFunnels Pro versions <= 2.9.4 due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a specially crafted request to a vulnerable site. Successful exploitation requires a user to interact with a malicious link or page, allowing the attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to session hijacking or unauthorized actions performed on behalf of a logged-in administrator. The issue is resolved in version 2.9.5.

Affected products

  • WPFunnels WPFunnels Pro <= 2.9.4

Timeline

  • 2026-05-10: other: Reported by researcher dutafi
  • 2026-06-04: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD
  • 2026-06-17: patched: Patch available in version 2.9.5

References