Impact
Unauthenticated Cross Site Scripting is present in WPFunnels plugin versions up to 3.13.1. The flaw allows an attacker to inject malicious script that executes in the browser of anyone who views a page that loads the vulnerable plugin. This can result in session hijacking, credential theft, or defacement of the site. The impact is confined to client‑side code execution, but the potential damage to user data and trusted communications is significant.
Affected Systems
WordPress sites that installed the WPFunnels plugin version 3.13.1 or earlier are affected. Updating to version 3.13.2 or later removes the flaw.
Risk and Exploitability
The CVSS score of 7.1 reflects a moderate to high severity, and because the vulnerability is unauthenticated the attacker does not require any credentials to exploit it. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no widespread exploitation reports yet. The likely attack vector is through any input path provided by the plugin that is rendered without proper sanitization, allowing a malicious payload to be stored or reflected in a page viewed by visitors.
OpenCVE Enrichment