Impact
The WPFunnels plugin for WordPress contains a missing authorization flaw that allows an attacker to invoke the wpfnl_load_payment AJAX action without authentication. Because the underlying add_offer_product_to_cart() function performs no nonce verification, capability check, or validation of the supplied product ID against the configured funnel step, unauthenticated users can add any WooCommerce product to the cart at the discounted price defined in the funnel step.
Affected Systems
This vulnerability affects all installations of the WPFunnels plugin for WordPress up to and including version 3.12.13. The plugin, known as Funnel Builder for WooCommerce with Checkout & One Click Upsell, is available from the getwpfunnels vendor.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and no EPSS score is published. The flaw is not listed in the CISA KEV catalog. The attack vector is likely an unauthenticated HTTP request to the wpfnl_load_payment endpoint. Attackers can manipulate price and revenue, potentially leading to significant financial loss if the site processes a large volume of orders.
OpenCVE Enrichment