Loading market data...
← Back to CVE feed

CVE-2026-79632

MEDIUM CVSS 5.3 View on NVD ↗

Description

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Published: Sep 04, 2026 07:17 UTC Modified: Sep 04, 2026 13:20 UTC