CVE-2025-12468: FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure
The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.4.1 via the '/wc-coupons/' REST API endpoint. This is due to the endpoint being marked as a public API (publicapi = true), which results in the endpoint being registered with permissioncallback => 'returntrue', bypassing all authentication and capability checks. This makes it possible for unauthenticated attackers to extract sensitive data including all WooCommerce coupon codes, coupon IDs, and expiration status.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12468?
CVE-2025-12468 has been assessed as a high severity vulnerability due to sensitive information exposure.
How do I fix CVE-2025-12468?
To fix CVE-2025-12468, update the FunnelKit Automations plugin to the latest version beyond 3.6.4.1.
What versions are affected by CVE-2025-12468?
CVE-2025-12468 affects all versions up to and including version 3.6.4.1 of the FunnelKit Automations plugin.
What kind of information is exposed by CVE-2025-12468?
CVE-2025-12468 can expose sensitive information via the '/wc-coupons/' REST API endpoint.
Is there a workaround for CVE-2025-12468 if I cannot update immediately?
There are currently no known workarounds for CVE-2025-12468, so updating the plugin is the recommended action.