CVE detail
CVE-2026-14345
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.12.7 via the 'postData' parameter parameter. This is due to unsanitized write of attacker-controlled postData values into a PHP-includeable .log file combined with the use of include_once to render that file in wpfnl_show_log. This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the Log Settings "Enable Logs" toggle is on and that an administrator subsequently opens the polluted log file via the plugin's Log Settings View UI; however, the nonce required to reach the optin endpoint is publicly emitted on every funnel step page, so the injection step itself is fully unauthenticated.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 12
- within the 30d window
- Peak daily
- 11
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)Wordfence
.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13039 Patch Status Patched Published Jul 9, 2026 Affected Software Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) [wp-event-solution] Researcher Niv Kochan More Details > Flatsome FundEngine – Do
vendorwww.wordfence.comJul 16, 2026, 8:29 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/5d84d749-0ab5-49dd-8e4f-45681f197742?source=cvewww.wordfence.com
No excerpt available.
Third Party Advisorywww.wordfence.comJul 7, 2026, 6:16 AM - https://plugins.trac.wordpress.org/changeset?old_path=%2Fwpfunnels/tags/3.12.7&new_path=%2Fwpfunnels/tags/3.12.8plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 7, 2026, 6:16 AM - https://plugins.trac.wordpress.org/changeset/3597260/wpfunnels/trunk/admin/modules/settings/class-wpfnl-settings.phpplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 7, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/public/class-wpfnl-public.php#L1185plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 7, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/includes/core/classes/class-wpfnl-ajax-handler.php#L523plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 7, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/includes/core/classes/class-wpfnl-ajax-handler.php#L39plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 7, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.7/admin/modules/settings/class-wpfnl-settings.php#L709plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 7, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/public/class-wpfnl-public.php#L1185plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 7, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/includes/core/classes/class-wpfnl-ajax-handler.php#L523plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 7, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/includes/core/classes/class-wpfnl-ajax-handler.php#L39plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 7, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/wpfunnels/tags/3.12.5/admin/modules/settings/class-wpfnl-settings.php#L709plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 7, 2026, 6:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-65461CVSS 9.1 · Critical
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- CVE-2026-65455CVSS 9.1 · Critical
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- CVE-2026-27064CVSS 9.1 · Critical
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
- CVE-2026-14282CVSS 9.8 · Critical
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versio…
- CVE-2026-63048CVSS 9.4 · Critical
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload,…
- CVE-2026-16451CVSS 2.1 · Low
A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of…