Impact
The vulnerability exists in the WPFunnels WordPress plugin before version 3.13.0 and allows an unauthenticated attacker to create new WordPress user accounts without administrative or registration permissions. The plugin incorrectly trusts a value supplied in the opt‑in form submission instead of checking whether the site has user registration enabled in its settings. This flaw effectively bypasses the authentication requirement for account creation, enabling an attacker to add arbitrary user accounts and potentially gain access to privileged functions that regionally assigned accounts might possess. The weakness represents a classic improper access control or authentication bypass, allowing an attacker to alter the site’s user base without needing existing credentials.
Affected Systems
WordPress installations using the WPFunnels plugin older than version 3.13.0 are affected. The vulnerability impacts any site where the plugin’s opt‑in forms are enabled, regardless of the site registration setting. It does not require any additional software or specific server configuration beyond the presence of the plugin.
Risk and Exploitability
The flaw can be exploited over the network by submitting crafted opt‑in form requests to the plugin’s processing endpoint; no authentication or privileged access is needed. The lack of a formal CVSS score and EPSS data means exact severity metrics are unavailable, but the ability to create arbitrary accounts carries high potential for privilege escalation or malicious site activity. The vulnerability is not listed as a known exploited vulnerability in the CISA KEV catalog, and no current proof‑of‑concept exploits have been publicly disclosed. However, the attack vector is straightforward and the conditions for exploitation are minimal, indicating a strong potential for misuse by attackers, especially on sites with a large number of opt‑in form visitors.
OpenCVE Enrichment