Impact
The vulnerability in the WPFunnels WordPress plugin permits unauthenticated users to access log files stored in the publicly accessible uploads directory. When logging is enabled, these files contain customer order details and opt‑in form submissions, exposing sensitive personal information. The weakness effectively allows any internet user to download potentially GDPR‑compliant data without authorization.
Affected Systems
All installations of WPFunnels prior to version 3.13.0 are affected. Any WordPress site that has the plugin installed and has logging enabled could expose order data and personal information to attackers.
Risk and Exploitability
The CVSS rating is not provided, but the EPSS score is unavailable, and the vulnerability is not in CISA’s KEV catalog. Attackers need only to know the predictable path to the log files and can retrieve them with a simple GET request. Because no authentication is required, the risk of data leakage is significant, especially if log data contains personal or financial details. Organizations should treat this as a high‑risk disclosure.
OpenCVE Enrichment