CVE-2026-97269: WordPress WPFunnels plugin <= 3.13.1 - Insecure Direct Object References (IDOR) vulnerability
Published Oct 1, 2026
·Updated
Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.
Affected Software
1 affected component
WPFunnels WPFunnels<=3.13.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/wp-funnelsto a version that resolves this vulnerability.Fixed in 3.13.2
Event History
Oct 1, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerability is unauthenticated and requires no privileges or user interaction. The CVSS vector indicates it can be exploited over the network with low attack complexity.
2
How can I determine whether my site is affected?
Sites using the WPFunnels plugin are affected if the installed version is 3.13.1 or earlier.
3
What is the expected impact of successful exploitation?
The listed CVSS score is 6.5 (medium). Successful exploitation may result in low-impact disclosure of information and low-impact modification of information; no availability impact is indicated.