CVE-2026-14345Patch

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_show_log. This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the Log Settings "Enable Logs" toggle is on and that an administrator subsequently opens the polluted log file via the plugin's Log Settings View UI; however, the nonce required to reach the optin endpoint is publicly emitted on every funnel step page, so the injection step itself is fully unauthenticated.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-07-07); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-07: 1Mentions · 2026-07-13: 1Mentions · 2026-07-29: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-29: 107-0707-1307-29
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-071
Patch1
2026-07-131
Patch1
2026-07-291
Disclosure1
Full discourse3 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-14345 — CVSS 9.8/10 ██████████ The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/3yZ6f1VZxd

    Post summary

    The tweet announces CVE‑2026‑14345 with a high CVSS score and urges remediation, indicating the primary focus is on delivering a patch.

    10000115
    64 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-14345: WPFunnels Remote Code Execution Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04rf9VC0

    Post summary

    The text announces a new remote code execution vulnerability in WPFunnels and hints at business impact, but provides no technical or exploit details beyond the general classification.

    0000035
    32 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    📁 CVE-2026-14345: WPFunnels <=3.12.7 has unauthenticated RCE via malicious file upload through the 'postData' parameter. CVSS 9.8 — no login needed. Update past 3.12.7 now. #WordPress #cybersecurity https://secalerts.co/vulnerability/CVE-2026-14345?utm_campaign=x https://t.co/N0O80sDXdz

    Post summary

    CVE-2026-14345 exposes an unauthenticated RCE in WPFunnels via a malicious file upload, with a CVSS score of 9.8; users are advised to update beyond version 3.12.7 to mitigate the vulnerability.

    00000132
    858 followersView on X

Explore more