Missing Authorization Vulnerability in WPFunnels Plugin for WordPress
CVE-2026-84908
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-84908?
The WPFunnels plugin for WordPress has a significant vulnerability that allows unauthenticated attackers to exploit the plugin's AJAX actions. Specifically, the 'wpfnl_load_payment' action is exposed to both authenticated and unauthenticated users without proper nonce verification or checks on user capabilities. Through the add_offer_product_to_cart() function, an attacker can manipulate the cart by adding arbitrary WooCommerce products at unauthorized, potentially discounted prices. This could lead to serious revenue loss for website owners as it undermines the integrity of the checkout process.
Affected Version(s)
WPFunnels β Funnel Builder for WooCommerce with Checkout & One Click Upsell 0 <= 3.12.13