PT-2025-45544 · WordPress · Wpfunnels

Published

2025-11-08

·

Updated

2025-11-08

·

CVE-2025-12000

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPFunnels plugin for WordPress versions up to and including 3.6.2
Description The WPFunnels plugin for WordPress has a flaw that allows authenticated attackers with Administrator-level access or higher to delete arbitrary files on the server. This is due to inadequate file path validation within the wpfnl delete log() function. Deleting specific files, such as wp-config.php, could lead to remote code execution.
Recommendations Update the WPFunnels plugin to a version newer than 3.6.2.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-12000

Affected Products

Wpfunnels