Missing Authorization Vulnerability in WPFunnels Plugin for WordPress
CVE-2026-84908

5.3MEDIUM

What is CVE-2026-84908?

The WPFunnels plugin for WordPress has a significant vulnerability that allows unauthenticated attackers to exploit the plugin's AJAX actions. Specifically, the 'wpfnl_load_payment' action is exposed to both authenticated and unauthenticated users without proper nonce verification or checks on user capabilities. Through the add_offer_product_to_cart() function, an attacker can manipulate the cart by adding arbitrary WooCommerce products at unauthorized, potentially discounted prices. This could lead to serious revenue loss for website owners as it undermines the integrity of the checkout process.

Affected Version(s)

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell 0 <= 3.12.13

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.