Sceawere

Vulnerability Detail

CVE-2026-27371UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in WPFunnels

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
WPFunnels
Product
WPFunnels
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:18.910Z",
  "pubdate": "2026-09-30T13:17:18.910Z",
  "executiveSummary": "WPFunnels versions 3.13.1 and earlier contain an unauthenticated Cross-Site Scripting (XSS) vulnerability.\nThis flaw allows remote, unauthenticated attackers to inject malicious JavaScript into web pages viewed by other users.\nThe vulnerability poses a significant risk to site integrity and user session security.\nBy executing arbitrary code within the context of a victim's browser session, an attacker can perform actions on behalf of the user, steal session cookies, or redirect users to malicious domains.\nNo authentication is required for exploitation, significantly lowering the barrier for entry for potential threat actors.\nThe impact is categorized as high, as it could lead to full account takeover or administrative access if an administrator views the injected payload.",
  "technicalDetails": "The vulnerability stems from improper neutralization of user-supplied input before it is rendered in the browser. In WPFunnels versions up to 3.13.1, specific input vectors lack adequate sanitization or output encoding mechanisms.\nThe root cause is the failure of the application to enforce strict input validation or context-aware output encoding on parameters that are subsequently reflected in the HTTP response.\nThe exploitation flow begins with the attacker identifying a vulnerable parameter within the WPFunnels plugin. Because the vulnerability is unauthenticated, the attacker does not need to possess valid login credentials or specific administrative privileges to initiate the request.\nThe attacker crafts a malicious payload containing JavaScript, typically enclosed in <script> tags or injected into HTML event handlers (such as onerror or onload). This payload is submitted via a crafted HTTP GET or POST request to the target site.\nUpon receiving the request, the server reflects the unsanitized input directly into the rendered HTML content of the page. When an unsuspecting user, such as an administrator, navigates to the compromised page, the victim's browser interprets the injected JavaScript as legitimate code originating from the trusted domain.\nSince the payload executes within the security context of the victim's browser session, the attacker can access sensitive information stored in the Document Object Model (DOM), including session tokens, authentication cookies, and CSRF tokens.\nFurthermore, the attacker can perform unauthorized actions, such as modifying page content, exfiltrating sensitive data, or performing background requests to plugin configurations without the victim's knowledge or consent.\nThis unauthenticated XSS vector is accessible via standard network exposure, meaning any remote attacker capable of reaching the site can attempt to trigger the injection.\nBecause the vulnerability impacts the front-end rendering logic of WPFunnels, it persists until the plugin is updated or the underlying code is modified to implement robust output encoding (e.g., using WordPress standard esc_html() or esc_js() functions)."
}
CVE-2026-27371: Unauthenticated XSS in WPFunnels (HIGH Severity, CVSS: 7.1) | Sceawere