WordPress Plugin Vulnerabilities

WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode_optin_submission

Description

The plugin does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.

Proof of Concept

Affects Plugins

Fixed in 3.13.0

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Sai Praneeth Koti
Submitter
Sai Praneeth Koti
Verified
Yes

Timeline

Publicly Published
2026-09-02 (about 2 days ago)
Added
2026-09-02 (about 1 day ago)
Last Updated
2026-09-02 (about 1 day ago)

Other