CVE-2025-12469: FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending
The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.4.1. This is due to the plugin not properly verifying that a user is authorized to perform administrative actions in the bwfantestemail AJAX handler. The nonce used for verification is publicly exposed to all visitors (including unauthenticated users) via the frontend JavaScript localization, and the checknonce() function accepts low-privilege authenticated users who possess this nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send arbitrary emails from the site with attacker-controlled subject and body content.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12469?
CVE-2025-12469 is considered a high severity vulnerability due to its potential impact on unauthorized actions within the FunnelKit Automations plugin.
How do I fix CVE-2025-12469?
To fix CVE-2025-12469, update the FunnelKit Automations plugin to the latest version beyond 3.6.4.1.
What systems are affected by CVE-2025-12469?
CVE-2025-12469 affects all versions of the FunnelKit Automations plugin for WordPress and WooCommerce up to and including version 3.6.4.1.
Can CVE-2025-12469 lead to data breaches?
Yes, CVE-2025-12469 can potentially allow attackers to exploit missing authorization, leading to unauthorized access to sensitive data.
How can I check if my site is vulnerable to CVE-2025-12469?
Check your installed version of the FunnelKit Automations plugin; if it is version 3.6.4.1 or earlier, your site is vulnerable to CVE-2025-12469.