Description
The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_test_mail function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to send test emails to an arbitrary email address.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57734 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnsf_af2_test_mail function in versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to send test emails to an arbitrary email address. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Funnelforms Free <= 3.4 - Missing Authorization to Test Email Sending |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:57:29.375Z
Reserved: 2023-10-04T22:45:21.066Z
Link: CVE-2023-5419
No data.
Status : Modified
Published: 2023-11-22T16:15:12.660
Modified: 2026-04-08T18:18:27.443
Link: CVE-2023-5419
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD