CVE-2025-68582
8.8Funnelforms · Funnelforms Free
A missing authorization vulnerability in the Funnelforms Free WordPress plugin allows unauthenticated attackers to exploit incorrectly configured access control settings.
Executive summary
A critical missing authorization flaw in Funnelforms Free permits unauthenticated attackers to bypass access controls, posing a significant risk to site integrity.
Vulnerability
This vulnerability is a CWE-862 Missing Authorization flaw, which occurs because the plugin fails to perform adequate capability checks on sensitive functions. The vulnerability is exploitable by unauthenticated remote attackers.
Business impact
The ability for unauthenticated users to bypass access controls can lead to the unauthorized modification of form configurations, data manipulation, or potential disruption of business workflows. With a CVSS score of 8.8, this vulnerability is classified as High severity, as it allows attackers to interact with plugin functionality that should be restricted to administrative users.
Remediation
Immediate Action: Users should check the official WordPress plugin repository for an update that addresses this access control issue. If no update is available, deactivate and remove the plugin until a secure version is released.
Proactive Monitoring: Security teams should review web server access logs for anomalous requests directed at plugin endpoints, particularly those originating from unauthorized IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious or unauthorized requests to the plugin's administrative or configuration endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for unauthorized access to plugin settings, administrators must prioritize this issue. Organizations should verify if they are running the affected version and apply the vendor-provided patch immediately upon availability to prevent potential exploitation of the access control mechanism.
More Funnelforms CVEs
Sources
Originally found and disclosed by Legion Hunter | Patchstack Bug Bounty Program, per the CVE Program record.