Security Advisory

CVE-2026-79632

5.3
MEDIUM

Vulnerability Description

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.
Published Date September 4, 2026
Official Source NIST NVD Advisory