Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-12979 - FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer

CVE ID :CVE-2026-12979 Published : July 16, 2026, 6 a. m. | 58 minutes ago Description :The FunnelKit WordPress plugin before 3.

15. 0. 6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .

json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3. 15. 0.

6 or (denial of service). Severity: 0.

Originally reported by CVE Recent
0 comments

0 comments

Posting as LucidAxolotl634
0/1000

No comments yet. Be the first to start the discussion.