CVE Database
/

CVE-2025-7654

Back to search

CVE-2025-7654

Published: Aug 19, 2025

Modified: Apr 8, 2026

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including authentication cookies of other site users, which may make privilege escalation possible. Please note both FunnelKit – Funnel Builder for WooCommerce Checkout AND FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce are affected by this.

VendorProductVersions

amans2k

FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce

affected
0 - <= 3.6.3

amans2k

FunnelKit – Funnel Builder for WooCommerce Checkout

affected
0 - <= 3.11.0.2

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now