CVE-2025-12353

MEDIUM

WPFunnels <3.6.2 - Unauthorized Registration

Title source: llm
STIX 2.1

Description

The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 3.6.2. This is due to the plugin relying on a user controlled value 'optin_allow_registration' to determine if user registration is allowed, instead of the site-specific setting. This makes it possible for unauthenticated attackers to register new user accounts, even when user registration is disabled.

Scores

CVSS v3 5.3
EPSS 0.0012
EPSS Percentile 30.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
getwpfunnels/Easy WordPress Funnel Builder To Collect Leads And Increase Sales – WPFunnels < 3.6.2
getwpfunnels/WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell < 3.6.2
Published Nov 08, 2025
Tracked Since Feb 18, 2026