← Späť na vyhľadávanie CVE

CVE-2026-14345

WPFunnels

Popis

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the -postData- parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_show_log. This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the Log Settings -Enable Logs- toggle is on and that an administrator subsequently opens the polluted log file via the plugin-s Log Settings View UI; however, the nonce required to reach the optin endpoint is publicly emitted on every funnel step page, so the injection step itself is fully unauthenticated.

CVSS 9.8EPSS 0.745%Riziko 1.05
Zobraziť zdroj
Zverejnené
2026-07-07 06:16:22
Dotknuté verzie
<3.12.7
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H