This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 04 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
cvssV3_1
|
Fri, 04 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-287 |
Fri, 04 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled. This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths. | |
| Title | WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-04T12:57:04.603Z
Reserved: 2026-08-25T09:32:53.676Z
Link: CVE-2025-15691
Updated: 2026-09-04T12:56:57.668Z
Status : Received
Published: 2026-09-04T07:17:07.293
Modified: 2026-09-04T13:17:55.437
Link: CVE-2025-15691
No data.
OpenCVE Enrichment
Updated: 2026-09-04T07:30:15Z