Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Fri, 04 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getwpfunnels
Getwpfunnels wpfunnels Wordpress Wordpress wordpress |
|
| Vendors & Products |
Getwpfunnels
Getwpfunnels wpfunnels Wordpress Wordpress wordpress |
Fri, 04 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Fri, 04 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Fri, 04 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject. | |
| Title | WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode_optin_submission | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-04T12:53:12.964Z
Reserved: 2026-08-25T09:32:42.758Z
Link: CVE-2026-79632
No data.
Status : Received
Published: 2026-09-04T07:17:10.017
Modified: 2026-09-04T13:20:09.287
Link: CVE-2026-79632
No data.
OpenCVE Enrichment
Updated: 2026-09-04T17:30:17Z