Stats Digest Feeds
โ† Back to all CVEs

CVE-2025-15691

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Sep 04, 2026
Vendor unknown

Description

The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled. This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.

References