Description
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
Published: 2026-09-30
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Patch Now
AI Analysis

Impact

Unauthenticated Cross Site Scripting is present in WPFunnels plugin versions up to 3.13.1. The flaw allows an attacker to inject malicious script that executes in the browser of anyone who views a page that loads the vulnerable plugin. This can result in session hijacking, credential theft, or defacement of the site. The impact is confined to client‑side code execution, but the potential damage to user data and trusted communications is significant.

Affected Systems

WordPress sites that installed the WPFunnels plugin version 3.13.1 or earlier are affected. Updating to version 3.13.2 or later removes the flaw.

Risk and Exploitability

The CVSS score of 7.1 reflects a moderate to high severity, and because the vulnerability is unauthenticated the attacker does not require any credentials to exploit it. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no widespread exploitation reports yet. The likely attack vector is through any input path provided by the plugin that is rendered without proper sanitization, allowing a malicious payload to be stored or reflected in a page viewed by visitors.

Generated by OpenCVE AI on September 30, 2026 at 15:04 UTC.

Remediation

Vendor Solution

Update the WordPress WPFunnels plugin to the latest available version (at least 3.13.2).


OpenCVE Recommended Actions

  • Update WPFunnels to version 3.13.2 or newer
  • If an immediate update is not possible, disable or remove any form fields or data entry points that allow untrusted content to be processed by the plugin
  • Deploy a Web Application Firewall rule to block or sanitize suspicious script payloads

Generated by OpenCVE AI on September 30, 2026 at 15:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
Title WordPress WPFunnels plugin <= 3.13.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:37:18.077Z

Reserved: 2026-09-24T10:23:19.165Z

Link: CVE-2026-97271

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:38.040

Modified: 2026-09-30T14:18:16.950

Link: CVE-2026-97271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T15:15:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')