WPFunnels
cpe:2.3:a:getwpfunnels:wpfunnels:*:*:*:*:wordpress:*:*
- <= 3.12.8
A privilege escalation vulnerability has been identified in the WPFunnels plugin for WordPress, specifically in versions through 3.12.8. The issue arises in the 'update_settings()' REST callback, which fails to properly validate the 'group_id' path parameter against an allowlist of permitted option names. This oversight allows authenticated attackers with the 'wpf_manage_funnels' capability to target the 'wp_user_roles' option. By crafting a specific role definition and injecting it into the 'wp_user_roles' option, attackers can elevate their privileges to administrator level, granting full site access. The 'wpf_manage_funnels' capability is typically assigned to the Funnel Manager role, making this the minimum requirement for exploitation.
Exploitation of this vulnerability allows authenticated users with the 'wpf_manage_funnels' capability to gain administrator privileges on the WordPress site.
To reproduce this vulnerability, an authenticated user with the 'wpf_manage_funnels' capability can send a request to the 'update_settings' endpoint of the WPFunnels plugin's REST API. The request must include a 'group_id' parameter that targets the 'wp_user_roles' option, along with a 'settings_id' parameter specifying a role definition that includes arbitrary capabilities. Once the request is processed, the injected role definition will be applied, elevating the user's privileges to administrator.
Users are advised to update the WPFunnels plugin to version 3.12.9 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.