PatchSiren

WPFunnels CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WPFunnels CVE published 2026-06-17

CVE-2026-49778

CVE-2026-49778 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in WPFunnels Pro versions up to 2.9.4. The vulnerability has a CVSS score of 7.1 and is considered HIGH. It was published on 2026-06-17T13:20:46.830Z and last modified on 2026-06-17T17:17:23.307Z. Users of WPFunnels Pro should take immediate action to mitigate this vulnerability. The vulnerability allows attackers t [truncated]