WPFunnels WordPress Plugin Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing arbitrary file deletion has been identified in the WPFunnels plugin for WordPress, affecting all versions through 3.6.2. This issue arises from inadequate file path validation in the 'wpfnl_delete_log' function. As a result, authenticated attackers with Administrator-level access can delete any file on the server. Exploiting this vulnerability could lead to remote code execution, especially if a critical file like 'wp-config.php' is deleted.

Impact

Successful exploitation allows authenticated users with Administrator privileges to delete arbitrary files on the server. This could result in remote code execution if a sensitive file is removed.

Reproduction

To reproduce this vulnerability, an authenticated user with Administrator privileges can send a request to the 'wpfnl_delete_log' function. The request must include a 'logKey' payload that is not properly sanitized, allowing for path traversal. This can be done by manipulating the 'logKey' value to point to a file outside the intended directory, such as 'wp-config.php'.

Remediation

Users are advised to update the WPFunnels plugin to version 3.6.3 or later, where this vulnerability has been patched.

Added: Nov 8, 2025, 4:27 AM
Updated: Nov 8, 2025, 4:27 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
6.0
remediation
7.7
relevance
0.9
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.