CVE-2024-9186: Funnelkit Automations
High severity, CVSS 8.6. EPSS: 2.3% chance of exploitation in the next 30 days.
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks
Affected products
- Funnelkit Funnelkit Automations: before 3.3.0 (fixed in 3.3.0)
Published 2024-11-14. Last modified 2026-06-17.