Access violation vulnerability in Easy WordPress Funnel Builder To Collect Leads And Increase Sales – WPFunnels 3.6.2

The WPFunnels plugin used for WordPress has a security issue where it does not check the file path properly. This means that anyone who has Administrator access or higher can delete any file on the server, which can potentially allow them to take control of the website by deleting important files like wp-config.php.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.