Access Control Flaw in Funnelforms Free by Funnelforms
CVE-2025-68582

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 December 2025

What is CVE-2025-68582?

The Funnelforms Free plugin for WordPress has a missing authorization vulnerability that can be exploited due to incorrectly configured access control security levels. This flaw allows unauthorized access to sensitive functionalities, making it critical for users to ensure their versions do not exceed 3.8. Proper security measures and awareness of this vulnerability are essential to maintaining website integrity.

Affected Version(s)

Funnelforms Free <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Legion Hunter | Patchstack Bug Bounty Program
.
CVE-2025-68582 : Access Control Flaw in Funnelforms Free by Funnelforms