Sceawere
Vulnerability Detail
CVE-2026-97271UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in WPFunnels
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- WPFunnels
- Product
- WPFunnels
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:38.040Z",
"pubdate": "2026-09-30T13:17:38.040Z",
"executiveSummary": "WPFunnels versions 3.13.1 and below are susceptible to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.\nThe vulnerability originates from improper neutralization of user-supplied input before rendering it in the browser, allowing an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's session.\nSuccessful exploitation can result in unauthorized actions performed on behalf of authenticated users, session hijacking, or the defacement of the affected website.\nThis vulnerability is critical due to its unauthenticated nature, which lowers the barrier for entry for malicious actors to conduct reconnaissance or credential theft attacks.\nThe scope of impact is limited to the client-side environment of the user viewing the maliciously crafted URL, but if an administrator is targeted, it could lead to full site compromise.",
"technicalDetails": "The vulnerability is classified as Reflected Cross-Site Scripting (XSS) occurring due to insufficient input validation and output encoding within the affected WPFunnels plugin versions 3.13.1 and below.\nThe root cause lies in the application's failure to sanitize specific parameters passed via GET or POST requests before reflecting them back into the HTML response. When an attacker crafts a malicious URL containing a JavaScript payload within these vulnerable parameters, the server inadvertently includes this script in the rendered page sent to the victim's browser.\nThe attack flow proceeds as follows: First, the attacker identifies a publicly accessible endpoint within the plugin that reflects user input without context-aware encoding. Second, the attacker generates a malicious URL embedding the target JavaScript payload, often obfuscated to bypass basic filtering. Third, the attacker lures an authenticated user (typically an administrator or authorized plugin user) to click the link through social engineering or other vectors. Finally, the victim's browser executes the script in the context of the WordPress site, granting the attacker access to the user's document object model (DOM), cookies, and session tokens.\nBecause the vulnerability does not require authentication, an attacker can target any visitor or administrator visiting the site. The payload can be used to perform unauthorized administrative operations, exfiltrate sensitive cookies, or redirect users to malicious third-party domains.\nExploitation is facilitated by the lack of secure output encoding mechanisms, such as htmlspecialchars() or equivalent sanitization libraries, at the point of reflection. The vulnerability persists across all network environments where the plugin is active, making it highly accessible to external attackers.\nUpon successful execution, the script runs within the same origin as the legitimate site, successfully bypassing standard Same-Origin Policy (SOP) restrictions intended to protect user sessions. The post-exploitation impact includes persistent unauthorized control over administrative panels or automated content injection."
}