CVE-2026-84908: CWE-862 Missing Authorization in getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin versions up to 3.12.13 suffer from a missing authorization vulnerability. The plugin registers an AJAX action accessible to unauthenticated users without nonce verification or capability checks. This flaw allows attackers to add arbitrary WooCommerce products to a cart at discounted prices configured on any funnel step, enabling price manipulation and potential revenue loss.
AI Analysis
Technical Summary
The WPFunnels WordPress plugin is vulnerable due to the 'wpfnl_load_payment' AJAX action being accessible to both authenticated and unauthenticated users without proper authorization controls. The underlying function add_offer_product_to_cart() lacks nonce verification, capability checks, and validation that the product_id corresponds to the configured offer product for the specified funnel step_id. This missing authorization (CWE-862) enables unauthenticated attackers to manipulate cart contents by adding arbitrary products at discounted prices from any funnel step.
Potential Impact
Unauthenticated attackers can add arbitrary WooCommerce products to a victim's cart at discounted prices configured in funnel steps, leading to price manipulation and potential financial loss for the store owner. There is no impact on confidentiality or availability reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the AJAX action 'wpfnl_load_payment' to authenticated users only and implement nonce verification and capability checks in the add_offer_product_to_cart() function to ensure proper authorization and validation of product and funnel step IDs.
CVE-2026-84908: CWE-862 Missing Authorization in getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
Description
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin versions up to 3.12.13 suffer from a missing authorization vulnerability. The plugin registers an AJAX action accessible to unauthenticated users without nonce verification or capability checks. This flaw allows attackers to add arbitrary WooCommerce products to a cart at discounted prices configured on any funnel step, enabling price manipulation and potential revenue loss.
CVSS v3.1
Score 5.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The WPFunnels WordPress plugin is vulnerable due to the 'wpfnl_load_payment' AJAX action being accessible to both authenticated and unauthenticated users without proper authorization controls. The underlying function add_offer_product_to_cart() lacks nonce verification, capability checks, and validation that the product_id corresponds to the configured offer product for the specified funnel step_id. This missing authorization (CWE-862) enables unauthenticated attackers to manipulate cart contents by adding arbitrary products at discounted prices from any funnel step.
Potential Impact
Unauthenticated attackers can add arbitrary WooCommerce products to a victim's cart at discounted prices configured in funnel steps, leading to price manipulation and potential financial loss for the store owner. There is no impact on confidentiality or availability reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the AJAX action 'wpfnl_load_payment' to authenticated users only and implement nonce verification and capability checks in the add_offer_product_to_cart() function to ensure proper authorization and validation of product and funnel step IDs.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-09-02T15:42:15.416Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa0f0a5acd9273b49ccdede
Added to database: 09/09/2026, 05:37:41 UTC
Last enriched: 09/09/2026, 05:52:41 UTC
Last updated: 09/09/2026, 06:03:24 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.