CVE-2025-54696: WordPress WPFunnels plugin <= 3.5.26 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels allows Stored XSS. This issue affects WPFunnels: from n/a through 3.5.26.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels allows Stored XSS.This issue affects WPFunnels: from n/a through <= 3.5.26.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54696?
CVE-2025-54696 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-54696?
To fix CVE-2025-54696, update WPFunnels to version 3.5.27 or later.
What types of software are affected by CVE-2025-54696?
CVE-2025-54696 affects WPFunnels versions up to and including 3.5.26 and the WordPress WPFunnels Plugin.
What specific vulnerability does CVE-2025-54696 exploit?
CVE-2025-54696 exploits improper neutralization of input during web page generation, leading to stored cross-site scripting.
Can CVE-2025-54696 affect website security?
Yes, CVE-2025-54696 can significantly compromise website security by allowing attackers to execute malicious scripts in the context of a user's browser.