Unauthenticated Access Control Flaw in WPFunnels Plugin
CVE-2026-84754
6.5MEDIUM
What is CVE-2026-84754?
An unauthenticated access control vulnerability exists in WPFunnels plugin versions up to 3.12.13 that allows unauthorized users to access restricted areas of the application. This flaw can potentially enable attackers to bypass security mechanisms, leading to unauthorized actions within the WordPress environment. Administrators are advised to update to the latest version of the plugin to mitigate risks associated with this vulnerability.
Affected Version(s)
WPFunnels <= 3.12.13
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdullah Kareem "cyberkareem" | Patchstack Bug Bounty Program