CVE-2025-12353 Details
Description
The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 3.6.2. This is due to the plugin relying on a user controlled value 'optin_allow_registration' to determine if user registration is allowed, instead of the site-specific setting. This makes it possible for unauthenticated attackers to register new user accounts, even when user registration is disabled.
A vulnerability exists in the WPFunnels WordPress plugin, specifically in versions up to and including 3.6.2, allowing unauthorized user registration. The issue arises because the plugin uses a user-controlled value, 'optin_allow_registration', to manage registration permissions, rather than adhering to the site's default settings. This flaw enables unauthenticated attackers to create new user accounts, even when registration is disabled.
Users are advised to update the WPFunnels WordPress plugin to version 3.6.3 or a later patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 8, 2025CISA-ADP
Assessed Nov 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WPFunnels | <= 3.6.2 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 8, 2025 | New CVE Received | [email protected] |
Volerion