CVE-2025-68582

8.8

Funnelforms · Funnelforms Free

A missing authorization vulnerability in the Funnelforms Free WordPress plugin allows unauthenticated attackers to exploit incorrectly configured access control settings.

Executive summary

A critical missing authorization flaw in Funnelforms Free permits unauthenticated attackers to bypass access controls, posing a significant risk to site integrity.

Vulnerability

This vulnerability is a CWE-862 Missing Authorization flaw, which occurs because the plugin fails to perform adequate capability checks on sensitive functions. The vulnerability is exploitable by unauthenticated remote attackers.

Business impact

The ability for unauthenticated users to bypass access controls can lead to the unauthorized modification of form configurations, data manipulation, or potential disruption of business workflows. With a CVSS score of 8.8, this vulnerability is classified as High severity, as it allows attackers to interact with plugin functionality that should be restricted to administrative users.

Remediation

Immediate Action: Users should check the official WordPress plugin repository for an update that addresses this access control issue. If no update is available, deactivate and remove the plugin until a secure version is released.

Proactive Monitoring: Security teams should review web server access logs for anomalous requests directed at plugin endpoints, particularly those originating from unauthorized IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious or unauthorized requests to the plugin's administrative or configuration endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for unauthorized access to plugin settings, administrators must prioritize this issue. Organizations should verify if they are running the affected version and apply the vendor-provided patch immediately upon availability to prevent potential exploitation of the access control mechanism.

More Funnelforms CVEs

Sources

Originally found and disclosed by Legion Hunter | Patchstack Bug Bounty Program, per the CVE Program record.