Open Redirect Vulnerability in FunnelKit Automation by Autonami
CVE-2025-49868

4.7MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2025

What is CVE-2025-49868?

FunnelKit Automation by Autonami is susceptible to a URL redirection vulnerability that could allow unauthorized redirection to untrusted sites, potentially leading to phishing attacks. This flaw affects all versions up to and including 3.6.0, posing significant security risks to users who may inadvertently be directed to malicious websites. Proper validation of URLs is essential to mitigate these risks.

Affected Version(s)

Automation By Autonami <= 3.6.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.