FunnelKit
cpe:2.3:a:funnelkit:funnel_builder:*:*:*:*:wordpress:*:*
- < 3.15.0.6
A vulnerability exists in the FunnelKit WordPress plugin in versions prior to 3.15.0.6. The issue arises because the plugin does not properly validate user-supplied file paths before deleting files during a template import process. This flaw enables users with administrator privileges to exploit path traversal to delete arbitrary .json files outside the designated directory. Such actions can disrupt the functionality of other FunnelKit components or WordPress plugins, leading to a denial-of-service condition.
Exploitation of this vulnerability allows for arbitrary file deletion, which can disrupt the operation of other WordPress plugins or themes.
To reproduce this vulnerability, an administrator must first ensure that the FunnelKit WordPress plugin is active, along with WooCommerce. At least one funnel should be created. The vulnerability can be exploited by sending a POST request to the 'funnelkit-app' REST endpoint, including a traversal payload in the 'template' field. The 'builder' value must correspond to an existing directory on the server. After the request is processed, the targeted .json file will be deleted, demonstrating the successful exploitation of the vulnerability.
Users are advised to update the FunnelKit WordPress plugin to version 3.15.0.6 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.