plugin

Wp Marketing Automations Vulnerabilities

25 known security issues reported for the Wp Marketing Automations WordPress plugin. Most recent disclosed Apr 22, 2026.

1 critical 4 high 8 medium

Running Wp Marketing Automations on your site? Check whether your installed version is affected.

Scan your site free

FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.7.3 - Missing Authorization

medium

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.7.3. This makes it possible for authenticated attackers, with Subscriber-level acce...

CVSS:
4.3
Affected:
up to 3.7.3
Fixed in:
3.8.0
Disclosed:
Apr 22, 2026

CVE-2026-39450 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 3.6.4.2

unknown

[en] The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.4.1. This is due to the plugin not properly verifying that a user is authorized to perform administrative actions in the `...

Affected:
up to 3.6.4.2
Fixed in:
3.6.4.2
Disclosed:
Nov 5, 2025

CVE-2025-12469 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 3.6.4.2

unknown

[en] The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.4.1 via the '/wc-coupons/' REST API endpoint. This is due to the endpoint being marked as a public API (`public_a...

Affected:
up to 3.6.4.2
Fixed in:
3.6.4.2
Disclosed:
Nov 5, 2025

CVE-2025-12468 on NVD →

FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure

medium

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.4.1 via the '/wc-coupons/' REST API endpoint. This is due to the endpoint being marked as a public API (`public_api =...

CVSS:
5.3
Affected:
up to 3.6.4.1
Fixed in:
3.6.4.2
Disclosed:
Nov 4, 2025

CVE-2025-12468 on NVD →

FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending

medium

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.4.1. This is due to the plugin not properly verifying that a user is authorized to perform administrative actions in the `bwfan...

CVSS:
4.3
Affected:
up to 3.6.4.1
Fixed in:
3.6.4.2
Disclosed:
Nov 4, 2025

CVE-2025-12469 on NVD →

Multiple Plugins By FunnelKit <= (Various Versions) - Authenticated (Contributor+) Sensitive Information Exposure to Privilege Escalation via Woofunnel Library

high

Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including authentication cookies of other site users, which may make privilege escalation po...

CVSS:
8.8
Affected:
up to 3.6.3
Fixed in:
3.6.4
Disclosed:
Aug 18, 2025

CVE-2025-7654 on NVD →

Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation

critical

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_or_activate_addon_plugins() function and a weak nonce hash in all versions up to, and...

CVSS:
9.8
Affected:
up to 3.5.3
Fixed in:
3.6.0
Disclosed:
Jun 17, 2025

CVE-2025-1562 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 3.6.1

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FunnelKit Automation By Autonami allows Phishing. This issue affects Automation By Autonami: from n/a through 3.6.0.

Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
Jun 17, 2025

CVE-2025-49868 on NVD →

Automation By Autonami <= 3.6.0 - Open Redirect

medium

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.6.0. This is due to insufficient validation on a redirect url. This makes it possible for unauthenticated attackers to redirect users to...

CVSS:
6.1
Affected:
up to 3.6.0
Fixed in:
3.6.1
Disclosed:
Jun 12, 2025

CVE-2025-49868 on NVD →

Automation By Autonami <= 3.5.1 - Open Redirect

high

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.5.1. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect...

CVSS:
7.2
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Mar 27, 2025

CVE-2025-30795 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 3.5.2

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FunnelKit Automation By Autonami allows Phishing. This issue affects Automation By Autonami: from n/a through 3.5.1.

Affected:
up to 3.5.2
Fixed in:
3.5.2
Disclosed:
Mar 27, 2025

CVE-2025-30795 on NVD →

Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.1 - Unauthenticated SQL Injection via 'automationId'

high

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the ‘automationId’ parameter in all versions up to, and including, 3.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient pre...

CVSS:
7.5
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Mar 21, 2025

CVE-2025-2186 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 3.3.0

unknown

[en] The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

Affected:
up to 3.3.0
Fixed in:
3.3.0
Disclosed:
Nov 14, 2024

CVE-2024-9186 on NVD →

Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.2.2 - Unauthenticated SQL Injection

high

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the 'bwfan-track-id' parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient p...

CVSS:
7.5
Affected:
up to 3.2.2
Fixed in:
3.3.0
Disclosed:
Oct 24, 2024

CVE-2024-9186 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 3.2.0

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Automation By Autonami allows SQL Injection.This issue affects Automation By Autonami: from n/a through 3.1.2.

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Oct 21, 2024

CVE-2024-47328 on NVD →

Automation By Autonami <= 3.1.2 - Authenticated (Administrator+) SQL Injection

medium

The Automation By Autonami plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level a...

CVSS:
4.9
Affected:
up to 3.1.2
Fixed in:
3.2.0
Disclosed:
Sep 25, 2024

CVE-2024-47328 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 2.8.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Automation By Autonami allows Stored XSS.This issue affects Automation By Autonami: from n/a through 2.8.2.

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
Mar 21, 2024

CVE-2024-2580 on NVD →

Automation By Autonami <= 2.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Automation By Autonami plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 2.8.2
Fixed in:
2.8.3
Disclosed:
Mar 18, 2024

CVE-2024-2580 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 2.7.0

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit.This issue affects Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automa...

Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Dec 28, 2023

CVE-2023-50857 on NVD →

Automation By Autonami <= 2.6.1 - Authenticated(Administrator+) SQL Injection

medium

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 2.7.0 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...

CVSS:
6.6
Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Dec 21, 2023

CVE-2023-50857 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 2.1.2

unknown

[en] The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automations

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 22, 2022

CVE-2022-2389 on NVD →

Abandoned Cart Recovery for WooCommerce by Autonami <= 2.1.1 - Missing Authorization

medium

The Abandoned Cart Recovery for WooCommerce by Autonami plugin for WordPress is vulnerable to unauthorized execution of various AJAX actions due to insufficient capability checking and nonce validation on various AJAX actions and their hooked functions in versions up to, and including 2.1.1. This makes it possible for...

CVSS:
6.3
Affected:
up to 2.1.1
Fixed in:
2.1.2
Disclosed:
Jul 15, 2022

CVE-2022-2389 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 3.5.2

unknown
Affected:
up to 3.5.2
Fixed in:
3.5.2

CVE-2025-2186 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 3.6.0

unknown
Affected:
up to 3.6.0
Fixed in:
3.6.0

CVE-2025-1562 on NVD →

FunnelKit Automations &#8211; Email Marketing Automation and CRM for WordPress &amp; WooCommerce [wp-marketing-automations] < 3.6.4

unknown
Affected:
up to 3.6.4
Fixed in:
3.6.4

CVE-2025-7654 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database