Impact
The getwpfunnels:WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin contains a Local File Inclusion flaw that is triggered when the "logKey" parameter is supplied. An attacker with authenticated administrator privileges can craft a value for logKey that causes the plugin to include and execute arbitrary PHP files residing on the server. This enables the attacker to run any PHP code, effectively bypassing normal access controls, exfiltrating sensitive data, or taking complete control of the WordPress site and the underlying web server.
Affected Systems
All installations of the getwpfunnels:WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin up to and including version 3.12.7 are affected. The vulnerability applies to any WordPress site that has this plugin installed and an administrator or higher‑privileged user account exists. Non‑administrator users cannot trigger the flaw, but the presence of the vulnerable code in the plugin exposes the site to exploitation once an admin credential is available.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity, while the EPSS score of less than 1% denotes a low probability of exploitation. The vulnerability is not listed in KEV. Exploitation requires existing administrator authentication, meaning the attacker must have valid admin credentials—either through social engineering, credential theft, or compromising an existing admin account. Once authenticated, the attacker can trigger the LFI by passing a crafted "logKey" value, which causes execution of PHP code from a specified file.
OpenCVE Enrichment