CVE-2025-7654
19.08.2025, 08:15
Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including authentication cookies of other site users, which may make privilege escalation possible. Please note both FunnelKit Funnel Builder for WooCommerce Checkout AND FunnelKit Automations Email Marketing Automation and CRM for WordPress & WooCommerce are affected by this.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration
References