Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-14345: WPFunnels plugin for WordPress allows attackers to run code on the server.
CVE-2026-14345 · published 2 months ago
Summary
The WPFunnels plugin for WordPress has a security flaw that lets attackers run code on the server without needing a password. This can happen if administrators enable logging and then open a malicious log file. To stay safe, update the plugin to a fixed version or disable logging until the issue is resolved.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| getwpfunnels | wpfunnels – funnel builder for woocommerce with checkout & one click upsell | <= 3.12.7 |
Original advisory text
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'pos...
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_show_log. This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the Log Settings "Enable Logs" toggle is on and that an administrator subsequently opens the polluted log file via the plugin's Log Settings View UI; however, the nonce required to reach the optin endpoint is publicly emitted on every funnel step page, so the injection step itself is fully unauthenticated.
References
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/admin/modules/s...
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/includes/core/c...
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/includes/core/c...
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/public/class-wp...
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/admin/modules/s...
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/includes/core/c...
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/includes/core/c...
- https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/public/class-wp...
- https://plugins.trac.wordpress.org/changeset/3597260/wpfunnels/trunk/admin/modul...
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fwpfunnels/tags/3.12.7&n...
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5d84d749-0ab5-49dd-8e4...
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS 1%
Type
CWE-434Unrestricted File Upload
Timeline
Published7 Jul 2026
Updated22 Sep 2026
First seen7 Jul 2026
Track software like this
Free during beta