FunnelKit WordPress Plugin Path Traversal Vulnerability Allowing Arbitrary File Deletion

Vulnerability

A vulnerability exists in the FunnelKit WordPress plugin in versions prior to 3.15.0.6. The issue arises because the plugin does not properly validate user-supplied file paths before deleting files during a template import process. This flaw enables users with administrator privileges to exploit path traversal to delete arbitrary .json files outside the designated directory. Such actions can disrupt the functionality of other FunnelKit components or WordPress plugins, leading to a denial-of-service condition.

Impact

Exploitation of this vulnerability allows for arbitrary file deletion, which can disrupt the operation of other WordPress plugins or themes.

Reproduction

To reproduce this vulnerability, an administrator must first ensure that the FunnelKit WordPress plugin is active, along with WooCommerce. At least one funnel should be created. The vulnerability can be exploited by sending a POST request to the 'funnelkit-app' REST endpoint, including a traversal payload in the 'template' field. The 'builder' value must correspond to an existing directory on the server. After the request is processed, the targeted .json file will be deleted, demonstrating the successful exploitation of the vulnerability.

Remediation

Users are advised to update the FunnelKit WordPress plugin to version 3.15.0.6 or later.

Added: Jul 16, 2026, 7:22 AM
Updated: Jul 16, 2026, 7:22 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
6.3
remediation
7.7
relevance
9.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.