CVE-2025-12469
- EPSS 0.1%
- Veröffentlicht 05.11.2025 09:27:40
- Zuletzt bearbeitet 04.12.2025 14:03:18
The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.4.1. This is due to the plugin not properly verifying tha...
CVE-2025-12468
- EPSS 0.17%
- Veröffentlicht 05.11.2025 09:27:39
- Zuletzt bearbeitet 04.12.2025 14:01:37
The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.4.1 via the '/wc-coupons/' REST API endpoint. Th...
CVE-2025-1562
- EPSS 16.07%
- Veröffentlicht 18.06.2025 07:22:43
- Zuletzt bearbeitet 09.07.2025 18:55:22
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_or_activate_add...
CVE-2024-9186
- EPSS 26.8%
- Veröffentlicht 14.11.2024 06:15:07
- Zuletzt bearbeitet 15.05.2025 16:28:08
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthentic...
CVE-2024-47328
- EPSS 0.47%
- Veröffentlicht 21.10.2024 11:15:03
- Zuletzt bearbeitet 24.10.2024 13:45:07
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Automation By Autonami allows SQL Injection.This issue affects Automation By Autonami: from n/a through 3.1.2.
CVE-2023-50857
- EPSS 0.14%
- Veröffentlicht 28.12.2023 11:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:25
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit.This issue affects Recover WooCommerc...
CVE-2022-2389
- EPSS 0.15%
- Veröffentlicht 22.08.2022 15:15:14
- Zuletzt bearbeitet 21.11.2024 07:00:53
The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users...