CVE-2019-25151

MEDIUM

Funnel Builder <1.3.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the activate_plugin function in versions up to, and including, 1.3.0. This makes it possible for authenticated attackers to activate any plugin on the vulnerable service.

Scores

CVSS v3 5.4
EPSS 0.0072
EPSS Percentile 49.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269
Status published
Products (2)
brainstormforce/CartFlows – Funnel Builder & Checkout Plugin for WooCommerce < 1.3.0
cartflows/cartflows < 1.3.1
Published Jun 07, 2023
Tracked Since Feb 18, 2026