The WPFunnels plugin is vulnerable to Stored Cross-Site Scripting through the 'wpf_optin_form' shortcode, allowing attackers with contributor-level access to inject scripts into pages. This flaw affects versions up to 3.7.9 and is due to insufficient sanitization of the 'button_icon' parameter.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.