The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 3.6.2. This is due to the plugin relying on a user controlled value 'optin_allow_registration' to determine if user registration is allowed, instead of the site-specific setting. This makes it possible for unauthenticated attackers to register new user accounts, even when user registration is disabled.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getwpfunnels
Getwpfunnels wpfunnels Wordpress Wordpress wordpress |
|
| Vendors & Products |
Getwpfunnels
Getwpfunnels wpfunnels Wordpress Wordpress wordpress |
Sat, 08 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 3.6.2. This is due to the plugin relying on a user controlled value 'optin_allow_registration' to determine if user registration is allowed, instead of the site-specific setting. This makes it possible for unauthenticated attackers to register new user accounts, even when user registration is disabled. | |
| Title | WPFunnels <= 3.6.2 - Unauthorized User Registration | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-08T03:27:47.222Z
Updated: 2025-11-10T19:58:32.337Z
Reserved: 2025-10-27T15:11:29.679Z
Link: CVE-2025-12353
Updated: 2025-11-10T19:55:30.136Z
Status : Awaiting Analysis
Published: 2025-11-08T04:15:45.410
Modified: 2025-11-12T16:19:59.103
Link: CVE-2025-12353
No data.