CVE-2025-12353 | WPFunnels Plugin up to 3.6.2 on WordPress Setting optin_allow_registration improper authorization (EUVD-2025-38358)
A vulnerability was found in WPFunnels Plugin up to 3.6.2 on WordPress. It has been classified as critical. Affected is an unknown function of the component Setting Handler. Performing manipulation of the argument optin_allow_registration results in improper authorization.
This vulnerability is cataloged as CVE-2025-12353. It is possible to initiate the attack remotely. There is no exploit available.