rootpwn

high · CVSS v3 7.1

CVE-2026-97271

Unauthenticated cross‑site scripting (XSS) exists in WPFunnels plugin versions up to 3.13.1, allowing attackers to inject malicious scripts

Overview

Unauthenticated cross‑site scripting (XSS) exists in WPFunnels plugin versions up to 3.13.1, allowing attackers to inject malicious scripts into pages viewed by any user. The flaw can be triggered without authentication, making it trivial for an attacker to target site visitors. It is a high‑severity vulnerability with a CVSS v3 score of 7.1.

Description

Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.

Impact

The XSS flaw can compromise the confidentiality of user data, alter the integrity of web content, and potentially disrupt user experience. Site owners and visitors are at risk of session hijacking, data theft, or defacement. Defenders should treat this as a high‑impact issue that can affect all users of the affected plugin.

Remediation

1. Upgrade WPFunnels to version 3.13.2 or later, which removes the vulnerable code. 2. If an upgrade is not immediately possible, implement a web application firewall rule to block requests containing common XSS payloads. 3. Enable a strict Content Security Policy (CSP) that disallows inline scripts and restricts script sources to trusted domains. 4. Sanitize all user‑supplied input on the server side and escape output in templates.

Risk context

The vulnerability is rated high severity (CVSS 7.1) and has no EPSS data, indicating a potentially significant risk if left unpatched. Defenders should prioritize remediation to mitigate the risk of widespread exploitation.

Affected products

  • WPFunnels plugin

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.1
CVSS v4
—
EPSS
—

XSS WordPress WPFunnels WebSecurity HighSeverity InputValidation CSP

← All CVEs