Sceawere

Vulnerability Detail

CVE-2026-97271UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in WPFunnels

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
WPFunnels
Product
WPFunnels
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:38.040Z",
  "pubdate": "2026-09-30T13:17:38.040Z",
  "executiveSummary": "WPFunnels versions 3.13.1 and below are susceptible to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.\nThe vulnerability originates from improper neutralization of user-supplied input before rendering it in the browser, allowing an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's session.\nSuccessful exploitation can result in unauthorized actions performed on behalf of authenticated users, session hijacking, or the defacement of the affected website.\nThis vulnerability is critical due to its unauthenticated nature, which lowers the barrier for entry for malicious actors to conduct reconnaissance or credential theft attacks.\nThe scope of impact is limited to the client-side environment of the user viewing the maliciously crafted URL, but if an administrator is targeted, it could lead to full site compromise.",
  "technicalDetails": "The vulnerability is classified as Reflected Cross-Site Scripting (XSS) occurring due to insufficient input validation and output encoding within the affected WPFunnels plugin versions 3.13.1 and below.\nThe root cause lies in the application's failure to sanitize specific parameters passed via GET or POST requests before reflecting them back into the HTML response. When an attacker crafts a malicious URL containing a JavaScript payload within these vulnerable parameters, the server inadvertently includes this script in the rendered page sent to the victim's browser.\nThe attack flow proceeds as follows: First, the attacker identifies a publicly accessible endpoint within the plugin that reflects user input without context-aware encoding. Second, the attacker generates a malicious URL embedding the target JavaScript payload, often obfuscated to bypass basic filtering. Third, the attacker lures an authenticated user (typically an administrator or authorized plugin user) to click the link through social engineering or other vectors. Finally, the victim's browser executes the script in the context of the WordPress site, granting the attacker access to the user's document object model (DOM), cookies, and session tokens.\nBecause the vulnerability does not require authentication, an attacker can target any visitor or administrator visiting the site. The payload can be used to perform unauthorized administrative operations, exfiltrate sensitive cookies, or redirect users to malicious third-party domains.\nExploitation is facilitated by the lack of secure output encoding mechanisms, such as htmlspecialchars() or equivalent sanitization libraries, at the point of reflection. The vulnerability persists across all network environments where the plugin is active, making it highly accessible to external attackers.\nUpon successful execution, the script runs within the same origin as the legitimate site, successfully bypassing standard Same-Origin Policy (SOP) restrictions intended to protect user sessions. The post-exploitation impact includes persistent unauthorized control over administrative panels or automated content injection."
}
CVE-2026-97271: Unauthenticated XSS in WPFunnels (HIGH Severity, CVSS: 7.1) | Sceawere