The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled.
This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.
This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-287 |
Fri, 04 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled. This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths. | |
| Title | WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-04T06:00:02.523Z
Reserved: 2026-08-25T09:32:53.676Z
Link: CVE-2025-15691
No data.
Status : Received
Published: 2026-09-04T07:17:07.293
Modified: 2026-09-04T07:17:07.293
Link: CVE-2025-15691
No data.
OpenCVE Enrichment
Updated: 2026-09-04T07:30:15Z