CVE-2025-15691: Unknown Wpfunnels

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled. This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.

Affected products

  • Unknown Wpfunnels: from 3.6.3, before 3.13.0 (fixed in 3.13.0)

Published 2026-09-04. Last modified 2026-09-08.