The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 07:17
Updated : 2026-09-08 19:15
NVD link : CVE-2026-79632
Mitre link : CVE-2026-79632
CVE.ORG link : CVE-2026-79632
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
