Loading market data...
← Back to CVE feed

CVE-2025-15691

MEDIUM CVSS 5.3 View on NVD ↗

Description

The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled. This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Published: Sep 04, 2026 07:17 UTC Modified: Sep 04, 2026 13:17 UTC