CVE-2025-15691: Unknown Wpfunnels
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled. This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.
Affected products
- Unknown Wpfunnels: from 3.6.3, before 3.13.0 (fixed in 3.13.0)
Published 2026-09-04. Last modified 2026-09-08.