PT-2025-45553 · Automattic+1 · Woocommerce+1
Published
2025-11-08
·
Updated
2025-11-08
·
CVE-2025-12353
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales versions prior to 3.6.3
Description
The WPFunnels plugin for WordPress is susceptible to unauthorized user registration. The plugin incorrectly relies on a user-controlled value,
optin allow registration, to determine if user registration is permitted, rather than utilizing the site-specific setting. This allows unauthenticated attackers to create new user accounts, even when user registration is disabled on the WordPress site.Recommendations
Update WPFunnels to version 3.6.3 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpfunnels
Woocommerce