CVE-2026-84908 | getwpfunnels WPFunnels Plugin up to 3.12.13 on WordPress add_offer_product_to_cart product_id/step_id missing authentication (EUVD-2026-74687)

SecurityVulns

A vulnerability, which was classified as problematic, was found in getwpfunnels WPFunnels Plugin up to 3.12.13 on WordPress. Affected by this issue is the function add_offer_product_to_cart. Executing a manipulation of the argument product_id/step_id can lead to missing authentication.

This vulnerability appears as CVE-2026-84908. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More