CVE-2026-79632 PUBLISHED

WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode_optin_submission

Assigner: WPScan
Reserved: 25.08.2026 Published: 04.09.2026 Updated: 04.09.2026

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.

Product Status

Vendor Unknown
Product WPFunnels
Versions Default: unaffected
  • affected from 3.1.0 to 3.13.0 (excl.)

Credits

  • Sai Praneeth Koti finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE