CVE-2025-67571: WordPress WPFunnels plugin <= 3.6.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in WPFunnels WPFunnels wpfunnels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPFunnels: from n/a through <= 3.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPFunnels pluginto a version that resolves this vulnerability.Fixed in 3.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67571?
CVE-2025-67571 is classified as a medium severity vulnerability due to its missing authorization and potential for exploitation.
How do I fix CVE-2025-67571?
To fix CVE-2025-67571, update WPFunnels to the latest version beyond 3.6.2, where the missing authorization flaw is addressed.
What software is affected by CVE-2025-67571?
CVE-2025-67571 affects WPFunnels versions up to and including 3.6.2.
What type of vulnerability is CVE-2025-67571?
CVE-2025-67571 is a missing authorization vulnerability related to incorrectly configured access control security levels.
Can CVE-2025-67571 be exploited remotely?
Yes, CVE-2025-67571 can be exploited remotely if the access controls are incorrectly configured.