PatchSiren cyber security CVE debrief
CVE-2026-49778 WPFunnels CVE debrief
CVE-2026-49778 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in WPFunnels Pro versions up to 2.9.4. The vulnerability has a CVSS score of 7.1 and is considered HIGH. It was published on 2026-06-17T13:20:46.830Z and last modified on 2026-06-17T17:17:23.307Z. Users of WPFunnels Pro should take immediate action to mitigate this vulnerability. The vulnerability allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches. Administrators should update to a patched version as soon as possible. This vulnerability is a significant concern for WordPress users with WPFunnels Pro installed.
- Vendor
- WPFunnels
- Product
- WPFunnels Pro
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
WordPress administrators using WPFunnels Pro versions up to 2.9.4 should be aware of this vulnerability and take immediate action to protect their sites. Security teams and IT professionals responsible for managing WordPress installations should prioritize patching this vulnerability.
Technical summary
CVE-2026-49778 is an Unauthenticated Cross Site Scripting (XSS) vulnerability in WPFunnels Pro versions up to 2.9.4. The vulnerability has a CVSS score of 7.1 and is considered HIGH. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L. This vulnerability allows attackers to inject malicious scripts into web pages without requiring authentication, potentially leading to unauthorized actions or data breaches.
Defensive priority
High
Recommended defensive actions
- Update WPFunnels Pro to a patched version (if available) immediately.
- Implement a Web Application Firewall (WAF) to detect and prevent XSS attacks.
- Regularly monitor WordPress installations for updates and security patches.
- Use a security plugin to scan for vulnerabilities and monitor site integrity.
- Limit user privileges and access to sensitive areas of the WordPress site.
- Educate users about the risks of XSS attacks and the importance of keeping software up-to-date.
- Consider implementing a Content Security Policy (CSP) to mitigate XSS attacks.
Evidence notes
The vulnerability was reported by Patchstack and is documented in the CVE record. The CVE was published on 2026-06-17T13:20:46.830Z and last modified on 2026-06-17T17:17:23.307Z. The CVSS score and vector were provided by the NVD.
Official resources
-
CVE-2026-49778 CVE record
CVE.org
-
CVE-2026-49778 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
public