Impact
A flaw permits unauthenticated users to reference internal objects in the WordPress WPFunnels plugin, enabling them to view or manipulate data tied to other users or processes. The vulnerability directly undermines confidentiality by exposing details and can lead to broader privilege escalation if the data controls access to additional resources. The weakness is classified as CWE-639, “Authorization Bypass Through User-Controlled Key.”
Affected Systems
WordPress installations using the WPFunnels plugin version 3.13.1 or earlier. The vulnerability is present in all features of the plugin that construct object references from user-supplied values. Users must verify the current plugin version and whether it falls within the affected range.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity with potential for significant impact if exploited. The EPSS score is not available, so the likelihood of current exploitation cannot be precisely estimated; however, the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is unauthenticated and does not require advanced privileges, meaning any external actor can trigger the exploit by crafting requests with manipulated object identifiers.
OpenCVE Enrichment