Impact
The WPFunnels WordPress plugin prior to version 3.13.0 fails to verify whether the site’s user registration setting is enabled before creating accounts from opt‑in form submissions. The plugin trusts a value supplied in the request, which lets an unauthenticated attacker create new WordPress user accounts even when site registration is disabled. This flaw constitutes an improper access control vulnerability that allows the addition of arbitrary user accounts without any existing credentials.
Affected Systems
WordPress sites running WPFunnels versions older than 3.13.0 are affected. The issue arises when opt‑in forms are enabled on the site; it does not depend on other software components or specific server configurations beyond the presence of the plugin.
Risk and Exploitability
Exploitation can be achieved over the network by submitting a crafted opt‑in form request; no authentication is required. The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests low immediate exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and no public proof‑of‑concept exploits have been disclosed. However, an attacker can create a large number of unauthenticated accounts, which may be used for spam, phishing, or other malicious activities. The attack vector is straightforward and the necessary conditions for exploitation are minimal, implying a tangible risk for sites with publicly exposed opt‑in forms.
OpenCVE Enrichment