WordPress Plugin Vulnerabilities

WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms

Description

The plugin does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled.

This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.

Proof of Concept

Affects Plugins

Fixed in 3.13.0

References

Classification

Type
INCORRECT AUTHORISATION
CWE

Miscellaneous

Original Researcher
D01EXPLOIT OFFICIAL
Submitter
D01EXPLOIT OFFICIAL
Verified
Yes

Timeline

Publicly Published
2026-09-02 (about 2 days ago)
Added
2026-09-02 (about 1 day ago)
Last Updated
2026-09-02 (about 1 day ago)

Other