CVE-2026-79631
WPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-Accessible Log Files
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in form submissions when logging is enabled.
| Vendor | unknown |
| Product | wpfunnels |
| Published | Sep 4, 2026 |
| Last Updated | Sep 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpfunnels
Be the first to know when new medium vulnerabilities affecting unknown wpfunnels are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPFunnels
2.6.0 < 3.13.0
References
Credits
Abdullah Kareem WPScan