Filtered by vendor Funnelkit
Subscriptions
Filtered by product Funnelkit
Subscriptions
Total
2 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12978 | 2 Funnelkit, Wordpress | 2 Funnelkit, Wordpress | 2026-08-02 | 7.1 High |
| The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active. | ||||
| CVE-2026-12979 | 2 Funnelkit, Wordpress | 2 Funnelkit, Wordpress | 2026-08-02 | 5.5 Medium |
| The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3.15.0.6 or (denial of service). | ||||
Page 1 of 1.