{"schema_version":1,"title":"WPFunnels vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in WPFunnels: 0 in the last 7 days and 9 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84908, was published on 9 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/wpfunnels","json_url":"https://junglewise.ai/threats/vendors/wpfunnels.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/wpfunnels","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":2,"all_time":11,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":6,"last_90_days":9,"last_365_days":11},"latest":[{"cve":"CVE-2026-84908","cvss":5.3,"epss":0.0042,"slug":"cve-2026-84908-wpfunnels-missing-authorization-in-ajax-payment-handler","title":"WPFunnels missing authorization in AJAX payment handler","severity":"medium","exploited":false,"published_at":"2026-09-09T06:17:18.147+00:00","url":"https://junglewise.ai/threats/cve-2026-84908-wpfunnels-missing-authorization-in-ajax-payment-handler"},{"cve":"CVE-2026-79632","cvss":5.3,"epss":0.003,"slug":"cve-2026-79632-wpfunnels-plugin-unauthenticated-arbitrary-email-sending-in-opt","title":"WPFunnels plugin unauthenticated arbitrary email sending in opt-in handler","severity":"medium","exploited":false,"published_at":"2026-09-04T07:17:10.017+00:00","url":"https://junglewise.ai/threats/cve-2026-79632-wpfunnels-plugin-unauthenticated-arbitrary-email-sending-in-opt"},{"cve":"CVE-2026-79631","cvss":5.3,"epss":0.0035,"slug":"cve-2026-79631-wpfunnels-wordpress-plugin-information-disclosure-via-web","title":"WPFunnels WordPress plugin information disclosure via web-accessible logs","severity":"medium","exploited":false,"published_at":"2026-09-04T07:17:09.923+00:00","url":"https://junglewise.ai/threats/cve-2026-79631-wpfunnels-wordpress-plugin-information-disclosure-via-web"},{"cve":"CVE-2026-79630","cvss":5.3,"epss":0.003,"slug":"cve-2026-79630-wpfunnels-checkout-order-bump-product-substitution-allowing-price","title":"WPFunnels checkout order bump product substitution allowing price manipulation","severity":"medium","exploited":false,"published_at":"2026-09-04T07:17:09.817+00:00","url":"https://junglewise.ai/threats/cve-2026-79630-wpfunnels-checkout-order-bump-product-substitution-allowing-price"},{"cve":"CVE-2025-15691","cvss":5.3,"epss":0.0018,"slug":"cve-2025-15691-wpfunnels-wordpress-plugin-unauthenticated-user-registration","title":"WPFunnels WordPress plugin unauthenticated user registration bypass","severity":"medium","exploited":false,"published_at":"2026-09-04T07:17:07.293+00:00","url":"https://junglewise.ai/threats/cve-2025-15691-wpfunnels-wordpress-plugin-unauthenticated-user-registration"},{"cve":"CVE-2026-84754","cvss":6.5,"epss":0.0033,"slug":"cve-2026-84754-wpfunnels-broken-access-control-vulnerability","title":"WPFunnels broken access control vulnerability","severity":"medium","exploited":false,"published_at":"2026-09-03T17:17:25.797+00:00","url":"https://junglewise.ai/threats/cve-2026-84754-wpfunnels-broken-access-control-vulnerability"},{"cve":"CVE-2026-15103","cvss":8.8,"slug":"cve-2026-15103-wpfunnels-privilege-escalation-via-arbitrary-option-update","title":"WPFunnels privilege escalation via arbitrary option update","severity":"high","exploited":false,"published_at":"2026-07-16T09:16:17.677+00:00","url":"https://junglewise.ai/threats/cve-2026-15103-wpfunnels-privilege-escalation-via-arbitrary-option-update"},{"cve":"CVE-2026-13080","cvss":6.6,"slug":"cve-2026-13080-getwpfunnels-wpfunnels-local-file-inclusion-in-logkey-parameter","title":"getwpfunnels WPFunnels Local File Inclusion in logKey parameter","severity":"medium","exploited":false,"published_at":"2026-07-09T08:16:46.27+00:00","url":"https://junglewise.ai/threats/cve-2026-13080-getwpfunnels-wpfunnels-local-file-inclusion-in-logkey-parameter"},{"cve":"CVE-2026-14345","cvss":9.8,"slug":"cve-2026-14345-wpfunnels-remote-code-execution-via-log-file-inclusion","title":"WPFunnels remote code execution via log file inclusion","severity":"critical","exploited":false,"published_at":"2026-07-07T06:16:22.113+00:00","url":"https://junglewise.ai/threats/cve-2026-14345-wpfunnels-remote-code-execution-via-log-file-inclusion"},{"cve":"CVE-2026-49778","cvss":7.1,"epss":0.0019,"slug":"cve-2026-49778-wpfunnels-wpfunnels-pro-unauthenticated-xss","title":"WPFunnels WPFunnels Pro unauthenticated XSS","severity":"high","exploited":false,"published_at":"2026-06-17T13:20:46.83+00:00","url":"https://junglewise.ai/threats/cve-2026-49778-wpfunnels-wpfunnels-pro-unauthenticated-xss"},{"cve":"CVE-2026-0626","cvss":6.4,"epss":0.002,"slug":"cve-2026-0626-wpfunnels-stored-xss-in-wpf-optin-form-shortcode","title":"WPFunnels Stored XSS in wpf_optin_form shortcode","severity":"medium","exploited":false,"published_at":"2026-04-04T12:16:02.787+00:00","url":"https://junglewise.ai/threats/cve-2026-0626-wpfunnels-stored-xss-in-wpf-optin-form-shortcode"}],"vendor":{"hub":true,"name":"WPFunnels","slug":"wpfunnels","homepage":"https://getwpfunnels.com/","description":"A software company focused on sales funnel building tools for the WordPress ecosystem.","url":"https://junglewise.ai/threats/vendors/wpfunnels"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-14345","cvss":9.8,"slug":"cve-2026-14345-wpfunnels-remote-code-execution-via-log-file-inclusion","title":"WPFunnels remote code execution via log file inclusion","severity":"critical","exploited":false,"published_at":"2026-07-07T06:16:22.113+00:00","url":"https://junglewise.ai/threats/cve-2026-14345-wpfunnels-remote-code-execution-via-log-file-inclusion"},{"cve":"CVE-2026-15103","cvss":8.8,"slug":"cve-2026-15103-wpfunnels-privilege-escalation-via-arbitrary-option-update","title":"WPFunnels privilege escalation via arbitrary option update","severity":"high","exploited":false,"published_at":"2026-07-16T09:16:17.677+00:00","url":"https://junglewise.ai/threats/cve-2026-15103-wpfunnels-privilege-escalation-via-arbitrary-option-update"},{"cve":"CVE-2026-49778","cvss":7.1,"epss":0.0019,"slug":"cve-2026-49778-wpfunnels-wpfunnels-pro-unauthenticated-xss","title":"WPFunnels WPFunnels Pro unauthenticated XSS","severity":"high","exploited":false,"published_at":"2026-06-17T13:20:46.83+00:00","url":"https://junglewise.ai/threats/cve-2026-49778-wpfunnels-wpfunnels-pro-unauthenticated-xss"},{"cve":"CVE-2026-13080","cvss":6.6,"slug":"cve-2026-13080-getwpfunnels-wpfunnels-local-file-inclusion-in-logkey-parameter","title":"getwpfunnels WPFunnels Local File Inclusion in logKey parameter","severity":"medium","exploited":false,"published_at":"2026-07-09T08:16:46.27+00:00","url":"https://junglewise.ai/threats/cve-2026-13080-getwpfunnels-wpfunnels-local-file-inclusion-in-logkey-parameter"},{"cve":"CVE-2026-84754","cvss":6.5,"epss":0.0033,"slug":"cve-2026-84754-wpfunnels-broken-access-control-vulnerability","title":"WPFunnels broken access control vulnerability","severity":"medium","exploited":false,"published_at":"2026-09-03T17:17:25.797+00:00","url":"https://junglewise.ai/threats/cve-2026-84754-wpfunnels-broken-access-control-vulnerability"},{"cve":"CVE-2026-0626","cvss":6.4,"epss":0.002,"slug":"cve-2026-0626-wpfunnels-stored-xss-in-wpf-optin-form-shortcode","title":"WPFunnels Stored XSS in wpf_optin_form shortcode","severity":"medium","exploited":false,"published_at":"2026-04-04T12:16:02.787+00:00","url":"https://junglewise.ai/threats/cve-2026-0626-wpfunnels-stored-xss-in-wpf-optin-form-shortcode"},{"cve":"CVE-2026-84908","cvss":5.3,"epss":0.0042,"slug":"cve-2026-84908-wpfunnels-missing-authorization-in-ajax-payment-handler","title":"WPFunnels missing authorization in AJAX payment handler","severity":"medium","exploited":false,"published_at":"2026-09-09T06:17:18.147+00:00","url":"https://junglewise.ai/threats/cve-2026-84908-wpfunnels-missing-authorization-in-ajax-payment-handler"},{"cve":"CVE-2026-79631","cvss":5.3,"epss":0.0035,"slug":"cve-2026-79631-wpfunnels-wordpress-plugin-information-disclosure-via-web","title":"WPFunnels WordPress plugin information disclosure via web-accessible logs","severity":"medium","exploited":false,"published_at":"2026-09-04T07:17:09.923+00:00","url":"https://junglewise.ai/threats/cve-2026-79631-wpfunnels-wordpress-plugin-information-disclosure-via-web"},{"cve":"CVE-2026-79632","cvss":5.3,"epss":0.003,"slug":"cve-2026-79632-wpfunnels-plugin-unauthenticated-arbitrary-email-sending-in-opt","title":"WPFunnels plugin unauthenticated arbitrary email sending in opt-in handler","severity":"medium","exploited":false,"published_at":"2026-09-04T07:17:10.017+00:00","url":"https://junglewise.ai/threats/cve-2026-79632-wpfunnels-plugin-unauthenticated-arbitrary-email-sending-in-opt"},{"cve":"CVE-2026-79630","cvss":5.3,"epss":0.003,"slug":"cve-2026-79630-wpfunnels-checkout-order-bump-product-substitution-allowing-price","title":"WPFunnels checkout order bump product substitution allowing price manipulation","severity":"medium","exploited":false,"published_at":"2026-09-04T07:17:09.817+00:00","url":"https://junglewise.ai/threats/cve-2026-79630-wpfunnels-checkout-order-bump-product-substitution-allowing-price"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"WPFunnels","slug":"wpfunnels","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/wpfunnels"}]}