Extension WordPress

Vulnérabilités FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Cette page rassemble les failles publiées pour FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
1Critiques
13Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

13 fiches

CVE-2026-39450 Moyenne · 4,3
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.7.3 – Missing Authorization

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.7.3.…

Versions affectées

*-3.7.3

Correctif

3.8.0

Publication

22/04/2026

CVE-2025-12468 Moyenne · 5,3
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 – Unauthenticated Sensitive Information Exposure

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.4.1 via the '/wc-coupons/' REST API endpoint. This is…

Versions affectées

*-3.6.4.1

Correctif

3.6.4.2

Publication

04/11/2025

CVE-2025-12469 Moyenne · 4,3
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.4.1. This is due to the plugin not properly verifying…

Versions affectées

*-3.6.4.1

Correctif

3.6.4.2

Publication

04/11/2025

CVE-2025-7654 Élevée · 8,8
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Multiple Plugins By FunnelKit <= (Various Versions) – Authenticated (Contributor+) Sensitive Information Exposure to Privilege Escalation via Woofunnel Library

Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including authentication cookies of other site users, which may…

Versions affectées

*-3.6.3

Correctif

3.6.4

Publication

18/08/2025

CVE-2025-1562 Critique · 9,8
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 – Missing Authorization to Unauthenticated Arbitrary Plugin Installation

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_or_activate_addon_plugins() function and a weak nonce hash in…

Versions affectées

*-3.5.3

Correctif

3.6.0

Publication

17/06/2025

CVE-2025-49868 Moyenne · 6,1
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Automation By Autonami <= 3.6.0 – Open Redirect

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.6.0. This is due to insufficient validation on a redirect…

Versions affectées

*-3.6.0

Correctif

3.6.1

Publication

12/06/2025

CVE-2025-30795 Élevée · 7,2
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Automation By Autonami <= 3.5.1 – Open Redirect

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.5.1. This is due to insufficient validation on a redirect…

Versions affectées

*-3.5.1

Correctif

3.5.2

Publication

27/03/2025

CVE-2025-2186 Élevée · 7,5
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.1 – Unauthenticated SQL Injection via 'automationId'

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the ‘automationId’ parameter in all versions up to, and including, 3.5.1 due to insufficient escaping on the…

Versions affectées

*-3.5.1

Correctif

3.5.2

Publication

21/03/2025

CVE-2024-9186 Élevée · 7,5
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.2.2 – Unauthenticated SQL Injection

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the 'bwfan-track-id' parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the…

Versions affectées

*-3.2.2

Correctif

3.3.0

Publication

24/10/2024

CVE-2024-47328 Moyenne · 4,9
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Automation By Autonami <= 3.1.2 – Authenticated (Administrator+) SQL Injection

The Automation By Autonami plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-3.1.2

Correctif

3.2.0

Publication

25/09/2024

CVE-2024-2580 Moyenne · 6,4
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Automation By Autonami <= 2.8.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Automation By Autonami plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-2.8.2

Correctif

2.8.3

Publication

18/03/2024

CVE-2023-50857 Moyenne · 6,6
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Automation By Autonami <= 2.6.1 – Authenticated(Administrator+) SQL Injection

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 2.7.0 (exclusive) due to insufficient escaping on the user…

Versions affectées

[*, 2.7.0)

Correctif

2.7.0

Publication

21/12/2023

CVE-2022-2389 Moyenne · 6,3
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

Abandoned Cart Recovery for WooCommerce by Autonami <= 2.1.1 – Missing Authorization

The Abandoned Cart Recovery for WooCommerce by Autonami plugin for WordPress is vulnerable to unauthorized execution of various AJAX actions due to insufficient capability checking and nonce validation on various AJAX actions and their hooked functions in versions…

Versions affectées

*-2.1.1

Correctif

2.1.2

Publication

15/07/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités