Description

The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 3.6.2. This is due to the plugin relying on a user controlled value 'optin_allow_registration' to determine if user registration is allowed, instead of the site-specific setting. This makes it possible for unauthenticated attackers to register new user accounts, even when user registration is disabled.

INFO

Published Date :

2025-11-08T03:27:47.222Z

Last Modified :

2026-04-08T16:51:41.520Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-12353 vulnerability.

Vendors Products
Getwpfunnels
  • Wpfunnels
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact