WordPress WPFunnels Plugin <= 2.7.16 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-37977
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 July 2023
What is CVE-2023-37977?
The WPFunnels plugin for WordPress is susceptible to an unauthenticated reflected Cross-Site Scripting (XSS) vulnerability affecting versions 2.7.16 and earlier. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising user data and affecting site integrity. It is crucial for website owners to update to the latest version to mitigate this risk.
Affected Version(s)
Drag & Drop Sales Funnel Builder for WordPress β WPFunnels <= 2.7.16