Input validation vulnerability in FunnelKit Funnel Builder Pro 3.4.5

The FunnelKit Funnel Builder Pro plugin for WordPress has a security vulnerability that allows attackers to inject harmful code into posts. This can be done by using a function called ‘allow_iframe_tag_in_post’ which enables script and iframe tags to be used in all versions of the plugin, up to version 3.4.5. This means that if an attacker has contributor access or higher, they can insert code into pages that will run when someone visits that page.

Detected in:

FunnelKit Funnel Builder Pro fixed vulnerable versions: >= * <= 3.4.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.