CVE-2026-14345: CWE-434 Unrestricted Upload of File with Dangerous Type in getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_show_log. This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the Log Settings "Enable Logs" toggle is on and that an administrator subsequently opens the polluted log file via the plugin's Log Settings View UI; however, the nonce required to reach the optin endpoint is publicly emitted on every funnel step page, so the injection step itself is fully unauthenticated.
AI Analysis
Technical Summary
CVE-2026-14345 is a critical vulnerability in the WPFunnels plugin for WooCommerce (up to version 3.12.7) that allows unauthenticated remote code execution. The vulnerability stems from the unsafe handling of the 'postData' parameter, which is written without sanitization into a .log file that is subsequently included via PHP's include_once in the wpfnl_show_log function. Successful exploitation requires that logging is enabled and that an administrator views the compromised log file through the plugin's UI. The injection step is unauthenticated because the nonce needed to reach the optin endpoint is publicly available on funnel step pages.
Potential Impact
An attacker can execute arbitrary code on the server hosting the vulnerable plugin without authentication, leading to full compromise of confidentiality, integrity, and availability of the affected system. This includes the potential for complete server takeover if an administrator views the maliciously crafted log file while logging is enabled.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, it is recommended to disable the 'Enable Logs' setting in the plugin to prevent exploitation. Additionally, restrict administrator access to the plugin's log viewing interface to trusted personnel only.
CVE-2026-14345: CWE-434 Unrestricted Upload of File with Dangerous Type in getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
Description
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_show_log. This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the Log Settings "Enable Logs" toggle is on and that an administrator subsequently opens the polluted log file via the plugin's Log Settings View UI; however, the nonce required to reach the optin endpoint is publicly emitted on every funnel step page, so the injection step itself is fully unauthenticated.
CVSS v3.1
Score 9.8critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-14345 is a critical vulnerability in the WPFunnels plugin for WooCommerce (up to version 3.12.7) that allows unauthenticated remote code execution. The vulnerability stems from the unsafe handling of the 'postData' parameter, which is written without sanitization into a .log file that is subsequently included via PHP's include_once in the wpfnl_show_log function. Successful exploitation requires that logging is enabled and that an administrator views the compromised log file through the plugin's UI. The injection step is unauthenticated because the nonce needed to reach the optin endpoint is publicly available on funnel step pages.
Potential Impact
An attacker can execute arbitrary code on the server hosting the vulnerable plugin without authentication, leading to full compromise of confidentiality, integrity, and availability of the affected system. This includes the potential for complete server takeover if an administrator views the maliciously crafted log file while logging is enabled.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, it is recommended to disable the 'Enable Logs' setting in the plugin to prevent exploitation. Additionally, restrict administrator access to the plugin's log viewing interface to trusted personnel only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-07-01T15:32:02.804Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4c9b1127e9c797190cd901
Added to database: 07/07/2026, 06:22:09 UTC
Last enriched: 07/14/2026, 08:45:08 UTC
Last updated: 08/20/2026, 22:52:10 UTC
Views: 125
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.