WPFunnels
cpe:2.3:a:getwpfunnels:wpfunnels:*:*:*:*:wordpress:*:*
- <= 3.12.7
A local file inclusion vulnerability has been identified in the WPFunnels plugin for WordPress, specifically in versions through 3.12.7. The issue arises in the settings module, where the 'logKey' parameter can be exploited by authenticated users with administrator-level access. This vulnerability allows the inclusion and execution of arbitrary PHP files on the server, potentially leading to unauthorized access, data exposure, or code execution, especially in scenarios where uploaded PHP files can be included.
Exploitation of this vulnerability could result in unauthorized access to sensitive data, bypassing of access controls, or execution of malicious code on the server.
To reproduce this vulnerability, an authenticated user with administrator privileges can send a request to the WordPress site with the 'logKey' parameter. This parameter can be used to include and execute arbitrary PHP files from the server.
Users are advised to update the WPFunnels plugin to version 3.12.8 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.