WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell < 3.13.0 - Unauthenticated Product Price Manipulation
Strategic Overview
- Status
- Patched in 3.13.0
- Affected Version
< 3.13.0- CVSS
- 5.3Medium
- Weakness type
- CWE-602 · Client-Side Enforcement of Server-Side Security
- CVE
CVE-2026-79630
At a glance
CVE-2026-79630 is a medium-severity Client-Side Enforcement of Server-Side Security vulnerability in the WPFunnels WordPress plugin, affecting versions < 3.13.0. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 3.13.0; sites on affected versions should update now. Disclosed September 2026, reported by Aditya Gurav.
Vulnerability Overview
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to unauthorized price manipulation in all versions up to 3.13.0. This makes it possible for unauthenticated attackers to purchase items at a price not intended.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-602: Client-Side Enforcement of Server-Side Security
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Remediation
Update to version 3.13.0, or a newer patched version
How does WordSec protect against this?
This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: WPFunnels 3.13.0 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Other vulnerabilities in WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
- 9.8CVE-2026-14345: WPFunnels <= 3.12.7 Remote Code Execution
CVE-2026-14345 - 9.8CVE-2025-47530: WPFunnels <= 3.5.18 PHP Object Injection
CVE-2025-47530 - 8.8CVE-2026-15103: WPFunnels <= 3.12.8 Privilege Escalation
CVE-2026-15103 - 6.6CVE-2026-13080: WPFunnels <= 3.12.7 Local File Inclusion
CVE-2026-13080 - 6.5CVE-2025-12000: WPFunnels <= 3.6.2 Arbitrary File Deletion
CVE-2025-12000 - 6.4CVE-2026-0626: WPFunnels <= 3.7.9 Stored Cross-Site Scripting
CVE-2026-0626 - 6.4CVE-2025-54696: WPFunnels <= 3.5.26 Stored Cross-Site Scripting
CVE-2025-54696 - 6.4CVE-2023-0173: WPFunnels <= 2.6.8 Stored Cross-Site Scripting
CVE-2023-0173
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C