The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in form submissions when logging is enabled.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 07:17
Updated : 2026-09-08 19:15
NVD link : CVE-2026-79631
Mitre link : CVE-2026-79631
CVE.ORG link : CVE-2026-79631
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
