Access violation vulnerability in FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce 3.6.4.1

A popular plugin for WordPress called FunnelKit Automations has a security issue that can expose sensitive information. This issue affects all versions up to 3.6.4.1 and can be exploited through the plugin’s ‘/wc-coupons/’ REST API endpoint. This is because the endpoint is set as a public API, meaning it can be accessed without any authentication or capability checks. This allows attackers to get their hands on private data, such as WooCommerce coupon codes, coupon IDs, and expiration dates.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.