What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFunnels Team Drag & Drop Sales Funnel Builder for WordPress – WPFunnels plugin <= 2.7.16 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFunnels Team Drag & Drop Sales Funnel Builder for WordPress – WPFunnels plugin <= 2.7.16 versions.
Explanation of Vulnerability in Simple Terms
WPFunnels versions up to 2.7.16 contain a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into the plugin's interface. When a site visitor or admin interacts with a compromised funnel page, the injected script executes in their browser, potentially stealing session data or performing actions on their behalf. The vulnerability requires user interaction to trigger.
What an attacker can do
Inject malicious scripts that execute when users view funnel pages, stealing cookies or session tokens.
Potential impact on your site
Attackers can compromise visitor and admin sessions, redirect users, or deface funnel pages without needing a WordPress account.
Conditions required to exploit
No authentication required. Victim must visit a page containing the injected payload.
Key dates
External resources
Related vulnerabilities