#wpfunnels
CVE-2026-84753 - mail mint
The Mail Mint add‑on for WordPress (versions up to 1.31.0) can be tricked into executing unwanted commands without any login. This could let a stranger take control of your site…

Too many irrelevant or confusing CVEs? Use stackflag.com

#mailmint #wpfunnels #CVE #infosec
CVE-2026-84753: Mail Mint plugin can let attackers run code
The Mail Mint add‑on for WordPress (versions up to 1.31.0) can be tricked into executing unwanted commands without any login.
stackflag.com
September 3, 2026 at 6:50 PM
Special Offer! 🎉

Get a special 20% discount on WPFunnels pricing plans.

WPFunnels is the first canvas-based sales funnel builder that anyone can use without prior experience in funnel building.

Visit their site to avail the offer. 👇
wpdiscounts.io/offer...
Maximize Your Leads And Sales Using Marketing Funnel Automation In WordPress
A compact solution for marketers & digital creators to generate leads, convert prospects, and drive sales using conversion-optimized funnels and email ..
wpdiscounts.io
August 24, 2026 at 6:00 PM
CVE-2026-15103 - WPFunnels
CVE ID : CVE-2026-15103

Published : July 16, 2026, 9:16 a.m. | 1 hour, 18 minutes ago

Description : The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation v...
CVE-2026-15103 - WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This is due to the `update_settings()` REST callback failing to validate the `group_id` path parameter against an …
cvefeed.io
July 16, 2026 at 11:11 AM
Уязвимость CVE-2026-13080 в плагине WPFunnels для WooCommerce: угрозы и способы защиты

https://kripta.biz/posts/C5232808-7471-46EF-B763-4A9C59EE8639
July 9, 2026 at 10:35 PM
深度解析CVE-2026-13080漏洞:WPFunnels插件安全风险与应对策略

https://qian.cx/posts/9795F3EE-72A6-4F3F-B6DD-DCE8B625441B
July 9, 2026 at 10:35 PM
Drag & Drop Sales Funnel Builder for WordPress. Use WPFunnels to create high converting landing…
WPFunnels Pro v2.9.2
Drag & Drop Sales Funnel Builder for WordPress. Use WPFunnels to create high converting landing…
www.kerdchat.com
July 9, 2026 at 7:25 PM
🚨 EUVD-2026-42525
📊 6.6/10
🏢 getwpfunnels

📝 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all ver...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42525

#cybersecurity #infosec #cve #euvd
July 9, 2026 at 9:00 AM
Drag & Drop Sales Funnel Builder for WordPress. Use WPFunnels to create high converting landing…
WPFunnels Pro v2.9.6
Drag & Drop Sales Funnel Builder for WordPress. Use WPFunnels to create high converting landing…
www.kerdchat.com
July 7, 2026 at 8:53 PM
CVE-2026-14345 wpfunnels (CVSS Score 9.8)

#WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #hacking #wpsecurity #atomicedge #cybersecurity #malware #vulnerabilityresearch #cve #redteam #proofofconcept
CVE-2026-14345 – wpfunnels Proof of Concept - Atomic Edge
CVE-2026-14345 vulnerability in wpfunnels WordPress plugin. Proof of concept, ModSecurity rule, and patched version analysis by Atomic Edge.
atomicedge.io
July 7, 2026 at 3:16 PM
CVE-2026-14345. CVSS 9.8. WPFunnels lets attackers write code to your server. No auth required. Your wp-config.php, database credentials, everything is exposed.

Update to 3.12.7 now.

Scan your WordPress site: pulse-wp.com
#WordPress #RCE #CyberSecurity
July 7, 2026 at 12:00 PM
CVE-2026-14345 - WPFunnels
CVE ID : CVE-2026-14345

Published : July 7, 2026, 6:16 a.m. | 58 minutes ago

Description : The WPFunnels – Funnel Builder for WooCommerce with Checkout &amp; One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all ve...
CVE-2026-14345 - WPFunnels <= 3.12.7 - Unauthenticated Remote Code Execution via 'postData' Parameter
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file …
cvefeed.io
July 7, 2026 at 7:21 AM
CVE-2026-14345
The WPFunnels plugin for WordPress has a security flaw that lets attackers run code on the server without needing a password. This can happen if administrators enable logging and then open a malicious log file.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#CVE #infosec
CVE-2026-14345: WPFunnels plugin for WordPress allows attackers to run code on the server.
The WPFunnels plugin for WordPress has a security flaw that lets attackers run code on the server without needing a password.
stackflag.com
July 7, 2026 at 7:04 AM
🔴 CVE-2026-14345 - Critical (9.8)

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for Word...

https://www.thehackerwire.com/vulnerability/CVE-2026-14345/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
July 7, 2026 at 7:00 AM
🚨 EUVD-2026-42009
📊 9.8/10
🏢 getwpfunnels

📝 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all ve...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42009

#cybersecurity #infosec #cve #euvd
July 7, 2026 at 7:00 AM
Special 4th of July Offer! 🎉

Get a special 30% discount on WpFunnels pricing plans.

WPFunnels is the first canvas-based sales funnel builder that anyone can use without prior experience in funnel building.

Visit their site to avail the offer. 👇
wpdiscounts.io/offer...
Maximize Your Leads And Sales Using Marketing Funnel Automation In WordPress
A compact solution for marketers & digital creators to generate leads, convert prospects, and drive sales using conversion-optimized funnels and email ..
wpdiscounts.io
July 6, 2026 at 12:05 PM
Drag & Drop Sales Funnel Builder for WordPress. Use WPFunnels to create high converting landing…
WPFunnels Pro v2.9.6
Drag & Drop Sales Funnel Builder for WordPress. Use WPFunnels to create high converting landing…
www.kerdchat.com
July 3, 2026 at 3:32 PM
Drag & Drop Sales Funnel Builder for WordPress. Use WPFunnels to create high converting landing…
WPFunnels Pro v2.9.6
Drag & Drop Sales Funnel Builder for WordPress. Use WPFunnels to create high converting landing…
www.kerdchat.com
June 30, 2026 at 1:49 PM
Drag & Drop Sales Funnel Builder for WordPress. Use WPFunnels to create high converting landing…
WPFunnels Pro v2.9.6
Drag & Drop Sales Funnel Builder for WordPress. Use WPFunnels to create high converting landing…
www.kerdchat.com
June 23, 2026 at 1:57 PM
🚨 EUVD-2026-37624
📊 7.1/10
🏢 WPFunnels

📝 Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37624

#cybersecurity #infosec #cve #euvd
June 17, 2026 at 6:00 PM
June 15, 2026 at 7:27 PM
CVE-2026-49778 wpfunnels-pro (CVSS Score 7.2)

#WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #hacking #wpsecurity #atomicedge #cybersecurity #malware #vulnerabilityresearch #cve #redteam #proofofconcept
CVE-2026-49778 – wpfunnels-pro Proof of Concept - Atomic Edge
CVE-2026-49778 vulnerability in wpfunnels-pro WordPress plugin. Proof of concept, ModSecurity rule, and patched version analysis by Atomic Edge.
atomicedge.io
June 15, 2026 at 7:16 PM
🚨 EUVD-2026-31249
📊 4.3/10
🏢 WPFunnels Team

📝 Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint allows Retrieve Embedded Sensi...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31249

#cybersecurity #infosec #cve #euvd
May 21, 2026 at 9:01 AM
CVE-2025-69359: The WordPress LMS That Forgot to Ask Who You Are

#TheResident #cybersecurity #infosec #CVE202569359
CVE-2025-69359: The WordPress LMS That Forgot to Ask Who You Are
A medium-severity Missing Authorization flaw in WPFunnels' Creator LMS plugin (versions ≤ 1.1.12) — Patchstack's catalogue entry says "Broken Access Control," CVSS 5.3, no authentication required to reach the affected functionality. This is one of the most boring and most common shapes of WordPress
www.ehabhussein.com
April 25, 2026 at 5:02 AM
CVE-2026-0626 #WordPress plugin #vulnerability wpfunnels (CVSS Score 6.4) #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge
CVE-2026-0626 – wpfunnels Proof of Concept - Atomic Edge
CVE-2026-0626 vulnerability in wpfunnels WordPress plugin. Proof of concept, ModSecurity rule, and patched version analysis by Atomic Edge.
atomicedge.io
April 11, 2026 at 5:30 AM
🚨 EUVD-2026-18991
📊 6.4/10
🏢 getwpfunnels

📝 The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scr...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18991

#cybersecurity #infosec #cve #euvd
April 4, 2026 at 1:01 PM