N/A
2026-04-03< 3.8.0
WPFunnels <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpf_optin_form' Shortcode
Minimum safe version
3.8.0
Update to 3.8.0 or later to address 13 fixable vulnerabilities
WPFunnels <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpf_optin_form' Shortcode
CVE-2025-67571
CVE-2025-12353
CVE-2025-12000
CVE-2025-54696
CVE-2025-47530
CVE-2024-10792
CVE-2024-27965
CVE-2023-37977
WPFunnels <= 2.7.16 - Reflected Cross-Site Scripting
WordPress Drag & Drop Sales Funnel Builder for WordPress – WPFunnels Plugin < 2.7.16 is vulnerable to Insecure Direct Object References (IDOR)
WPFunnels <= 2.7.15 - Insecure Direct Object Reference
CVE-2023-0173