CVE-2026-79632 UNKNOWN

CVE-2026-79632

Published: 2026-09-04

Description

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…