Sceawere

Vulnerability Detail

CVE-2026-84754UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Access Control WPFunnels Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
WPFunnels
Product
WPFunnels
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-03T17:17:25.797Z",
  "pubdate": "2026-09-03T17:17:25.797Z",
  "executiveSummary": "The WordPress plugin WPFunnels, in versions up to 3.12.13, is susceptible to an unauthenticated broken access control vulnerability.\nThis vulnerability stems from a failure to properly implement authorization checks on specific endpoints within the plugin.\nThe flaw permits unauthenticated remote attackers to perform unauthorized actions or access sensitive functionalities that should be restricted to authenticated administrators.\nThe risk implication is significant as it potentially exposes the plugin's configuration, lead data, or site settings to unauthorized manipulation.\nExploitation requires no authentication and can be executed over the network by any visitor.\nThe impact includes potential unauthorized data modification, settings alteration, and a compromise of the integrity and confidentiality of the WordPress site's sales funnel operations.",
  "technicalDetails": "The vulnerability originates from missing or improperly implemented capability checks within the plugin's AJAX handler or REST API endpoints, which are responsible for processing critical plugin operations.\nIn versions up to 3.12.13, the plugin fails to perform necessary 'current_user_can()' checks or equivalent authentication validation on these endpoints.\nConsequently, the plugin processes requests from unauthenticated users as if they originated from a legitimate administrator.\nThe attack flow begins when an attacker identifies the exposed vulnerable endpoint, typically associated with WPFunnels funnel management or configuration data retrieval.\nThe attacker then crafts a malicious HTTP request (typically GET or POST) targeting these endpoints without providing valid authentication headers or session cookies.\nBecause the server-side code does not verify the user's role or session status before executing the associated function, the server proceeds to process the request's payload.\nThis allows the attacker to interact with the plugin's back-end logic, potentially leading to unauthorized data exfiltration, the modification of existing funnels, or the manipulation of global plugin settings.\nThe lack of access control effectively bypasses the WordPress security model, which normally ensures that administrative plugin actions are restricted to users with 'manage_options' or equivalent high-level permissions.\nPost-exploitation, an attacker could alter sales paths, inject malicious redirects, or harvest sensitive marketing and lead information gathered by the plugin, depending on the functionality exposed by the specific unprotected endpoint.\nThe vulnerability is critical due to the ease of exploitation, as it requires no prior knowledge of credentials or elevated account privileges."
}
CVE-2026-84754: Unauthenticated Access Control WPFunnels Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere