Unauthenticated Access Control Flaw in WPFunnels Plugin
CVE-2026-84754

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-84754?

An unauthenticated access control vulnerability exists in WPFunnels plugin versions up to 3.12.13 that allows unauthorized users to access restricted areas of the application. This flaw can potentially enable attackers to bypass security mechanisms, leading to unauthorized actions within the WordPress environment. Administrators are advised to update to the latest version of the plugin to mitigate risks associated with this vulnerability.

Affected Version(s)

WPFunnels <= 3.12.13

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdullah Kareem "cyberkareem" | Patchstack Bug Bounty Program
.