Junglewise Threat Intelligence

CVE-2026-84754: WPFunnels broken access control vulnerability

CVE-2026-84754 · Severity: medium · CVSS 6.5 · Published 2026-09-03

Technologies: WPFunnels. Vendors: WPFunnels.

Executive brief

WPFunnels is a popular WordPress plugin used to create marketing funnels and sales pages. This vulnerability allows unauthenticated attackers to access pages and perform actions they shouldn't be authorized to, potentially exposing sensitive funnel data and customer information. The flaw affects all versions up to 3.12.13 and has a CVSS score of 6.5 (medium severity).

Technical details

The vulnerability is a broken access control flaw in WPFunnels <= 3.12.13 that permits unauthenticated users to access restricted pages and perform unauthorized actions. The root cause stems from inadequate authorization checks on sensitive endpoints. No specific authentication or user interaction is required for exploitation—attackers can directly access restricted resources via network requests. This allows viewing of other users' funnel data and potentially modifying funnel configurations. The issue has been patched in version 3.13.0 and later.

Affected products

  • WPFunnels WPFunnels <=3.12.13

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Patched in version 3.13.0

References

Related threats