CVE-2026-12979: FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer
The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3.15.0.6 or (denial of service).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FunnelKit WordPress pluginto a version that resolves this vulnerability.Fixed in 3.15.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12979?
CVE-2026-12979 has a risk score of 25.
How do I fix CVE-2026-12979?
To fix CVE-2026-12979, update the FunnelKit WordPress plugin to version 3.15.0.6 or later.
Who is affected by CVE-2026-12979?
CVE-2026-12979 affects users of the FunnelKit WordPress plugin before version 3.15.0.6.
What types of files can be deleted due to CVE-2026-12979?
CVE-2026-12979 allows deletion of arbitrary .json files due to path traversal vulnerabilities.
What privileges are required to exploit CVE-2026-12979?
Exploitation of CVE-2026-12979 requires administrator privileges.