CVE-2026-84754: WordPress WPFunnels plugin <= 3.12.13 - Broken Access Control vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
Affected Software
1 affected component
WordPress WPFunnels<=3.12.13
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPFunnels Pluginto a version that resolves this vulnerability.Fixed in 3.13.0
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or any privileges to exploit it. It is remotely reachable over the network.
2
Which installations are affected?
WordPress sites using WPFunnels version 3.12.13 or earlier are affected according to the available information.
3
What impact can exploitation have?
The stated CVSS vector indicates low integrity impact and low availability impact. No confidentiality impact is identified.