Security Advisory
CVE-2026-79632
5.3
MEDIUM
Vulnerability Description
The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.
Published Date
September 4, 2026
Official Source
NIST NVD Advisory