CVE-2025-26979: WordPress Funnel Builder by FunnelKit plugin <= 3.9.0 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder allows PHP Local File Inclusion.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.9.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26979?
CVE-2025-26979 is classified as a critical vulnerability due to its potential for remote file inclusion leading to unauthorized access and system compromise.
How do I fix CVE-2025-26979?
To fix CVE-2025-26979, update FunnelKit Funnel Builder to version 3.9.1 or later where the vulnerability has been patched.
What versions of FunnelKit Funnel Builder are affected by CVE-2025-26979?
CVE-2025-26979 affects FunnelKit Funnel Builder versions up to and including 3.9.0.
What type of vulnerability is CVE-2025-26979?
CVE-2025-26979 is an improper control of filename for include/require statement vulnerability, commonly referred to as a local file inclusion vulnerability.
Can CVE-2025-26979 be exploited remotely?
Yes, CVE-2025-26979 can be exploited remotely by crafting malicious requests that manipulate the file inclusion mechanism.