CVE-2026-27371: WordPress WPFunnels plugin <= 3.13.1 - Reflected Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPFunnels pluginto a version that resolves this vulnerability.Fixed in 3.13.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WPFunnels account or prior access to the WordPress site. Exploitation still requires user interaction, as reflected XSS requires a victim to visit attacker-controlled or crafted input.
What impact can successful exploitation have?
The reported CVSS vector indicates low impacts to confidentiality, integrity, and availability, with scope changed. In practice, successful script execution occurs in the context of an affected site's user session.
Which versions should be treated as affected?
WPFunnels versions 3.13.1 and earlier are identified as affected. The provided information does not specify a fixed version.