Sceawere
Vulnerability Detail
CVE-2026-27371UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in WPFunnels
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- WPFunnels
- Product
- WPFunnels
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:18.910Z",
"pubdate": "2026-09-30T13:17:18.910Z",
"executiveSummary": "WPFunnels versions 3.13.1 and earlier contain an unauthenticated Cross-Site Scripting (XSS) vulnerability.\nThis flaw allows remote, unauthenticated attackers to inject malicious JavaScript into web pages viewed by other users.\nThe vulnerability poses a significant risk to site integrity and user session security.\nBy executing arbitrary code within the context of a victim's browser session, an attacker can perform actions on behalf of the user, steal session cookies, or redirect users to malicious domains.\nNo authentication is required for exploitation, significantly lowering the barrier for entry for potential threat actors.\nThe impact is categorized as high, as it could lead to full account takeover or administrative access if an administrator views the injected payload.",
"technicalDetails": "The vulnerability stems from improper neutralization of user-supplied input before it is rendered in the browser. In WPFunnels versions up to 3.13.1, specific input vectors lack adequate sanitization or output encoding mechanisms.\nThe root cause is the failure of the application to enforce strict input validation or context-aware output encoding on parameters that are subsequently reflected in the HTTP response.\nThe exploitation flow begins with the attacker identifying a vulnerable parameter within the WPFunnels plugin. Because the vulnerability is unauthenticated, the attacker does not need to possess valid login credentials or specific administrative privileges to initiate the request.\nThe attacker crafts a malicious payload containing JavaScript, typically enclosed in <script> tags or injected into HTML event handlers (such as onerror or onload). This payload is submitted via a crafted HTTP GET or POST request to the target site.\nUpon receiving the request, the server reflects the unsanitized input directly into the rendered HTML content of the page. When an unsuspecting user, such as an administrator, navigates to the compromised page, the victim's browser interprets the injected JavaScript as legitimate code originating from the trusted domain.\nSince the payload executes within the security context of the victim's browser session, the attacker can access sensitive information stored in the Document Object Model (DOM), including session tokens, authentication cookies, and CSRF tokens.\nFurthermore, the attacker can perform unauthorized actions, such as modifying page content, exfiltrating sensitive data, or performing background requests to plugin configurations without the victim's knowledge or consent.\nThis unauthenticated XSS vector is accessible via standard network exposure, meaning any remote attacker capable of reaching the site can attempt to trigger the injection.\nBecause the vulnerability impacts the front-end rendering logic of WPFunnels, it persists until the plugin is updated or the underlying code is modified to implement robust output encoding (e.g., using WordPress standard esc_html() or esc_js() functions)."
}