Sensitive Information Exposure in FunnelKit Automations for WooCommerce
CVE-2025-12468
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 November 2025
What is CVE-2025-12468?
The FunnelKit Automations plugin for WordPress is susceptible to a vulnerability that allows unauthorized access to sensitive information via the public REST API endpoint '/wc-coupons/'. This misconfiguration enables unauthenticated attackers to retrieve critical data such as WooCommerce coupon codes, IDs, and expiration statuses. This issue arises because the endpoint lacks proper authentication checks, exposing sensitive user information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FunnelKit Automations β Email Marketing Automation and CRM for WordPress & WooCommerce * <= 3.6.4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved