Beta

Report

FunnelKit Checkout <= 3.10.3 is vulnerable to Unauthenticated Arbitrary Post/Page Deletion vulnerability

Unauthenticated
Published
2023-12-26

The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on an unknown function in all versions up to, and including, 3.10.3. This makes it possible for unauthenticated attackers, to delete arbitrary content.

CVSS

Score:7.5

Severity:High

Version: 3.10.3

There is a patch available in v3.11.0 and we strongly recommend you update to this version as soon as possible.