CVE-2026-79632

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 07:17

Updated : 2026-09-08 19:15


NVD link : CVE-2026-79632

Mitre link : CVE-2026-79632

CVE.ORG link : CVE-2026-79632


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization