CVE-2026-84908
The WPFunnels plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.12.13. This is due to the plugin registering the 'wpfnl_load_payment' AJAX action for both authenticated and unauthenticated (wp_ajax_nopriv_) users and the underlying add_offer_product_to_cart() function performing no nonce verification, no capability check, and no validation that the attacker-supplied product_id is the offer product actually configured on the attacker-supplied step_id. This makes it possible for unauthenticated attackers to add arbitrary WooCommerce products to a cart at any discounted price configured on any funnel step, enabling price manipulation and revenue loss at checkout.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- CWE
- CWE-862
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
Weakness type
Related vulnerabilities
- CVE-2026-87997 — Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
- CVE-2026-87994 — Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
- CVE-2026-68484 — Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API....
- CVE-2026-86765 — Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint
- CVE-2026-86764 — Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components
- CVE-2026-86762 — Snipe-IT before 8.7.0 Authentication Bypass via API Middleware
- CVE-2026-86759 — Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer
- CVE-2026-86757 — Snipe-IT before 8.7.0 Information Disclosure via Custom Fields