Impact
The vulnerability in the WPFunnels WordPress plugin permits unauthenticated users to access log files stored in the publicly accessible uploads directory. When logging is enabled, these files contain customer order details and opt‑in form submissions, exposing sensitive personal information. The weakness effectively allows any internet user to download potentially GDPR‑compliant data without authorization.
Affected Systems
All installations of WPFunnels prior to version 3.13.0 are affected. Any WordPress site that has the plugin installed and has logging enabled could expose order data and personal information to attackers.
Risk and Exploitability
The CVSS rating is 5.3, the EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog. Attackers need only to know the predictable path to the log files and can retrieve them with a simple GET request. Because zero authentication is required, the potential for unintentional data leakage exists, but the overall risk is moderate given the CVSS and EPSS scores and the lack of active exploitation evidence. Organizations should still monitor for compromised data and consider temporary mitigations until a patch is applied.
OpenCVE Enrichment