high · CVSS v3 7.1
CVE-2026-97271
Unauthenticated cross‑site scripting (XSS) exists in WPFunnels plugin versions up to 3.13.1, allowing attackers to inject malicious scripts
Overview
Unauthenticated cross‑site scripting (XSS) exists in WPFunnels plugin versions up to 3.13.1, allowing attackers to inject malicious scripts into pages viewed by any user. The flaw can be triggered without authentication, making it trivial for an attacker to target site visitors. It is a high‑severity vulnerability with a CVSS v3 score of 7.1.
Description
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
Impact
The XSS flaw can compromise the confidentiality of user data, alter the integrity of web content, and potentially disrupt user experience. Site owners and visitors are at risk of session hijacking, data theft, or defacement. Defenders should treat this as a high‑impact issue that can affect all users of the affected plugin.
Remediation
1. Upgrade WPFunnels to version 3.13.2 or later, which removes the vulnerable code. 2. If an upgrade is not immediately possible, implement a web application firewall rule to block requests containing common XSS payloads. 3. Enable a strict Content Security Policy (CSP) that disallows inline scripts and restricts script sources to trusted domains. 4. Sanitize all user‑supplied input on the server side and escape output in templates.
Risk context
The vulnerability is rated high severity (CVSS 7.1) and has no EPSS data, indicating a potentially significant risk if left unpatched. Defenders should prioritize remediation to mitigate the risk of widespread exploitation.
Affected products
- WPFunnels plugin
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.1
- CVSS v4
- —
- EPSS
- —