FunnelKit Automations Missing Authorization Vulnerability (CVE-2025-12469) — Medium Severity Explained

The FunnelKit Automations plugin, a popular tool for email marketing and CRM in WordPress and WooCommerce environments, has been found to have a security vulnerability. This flaw, identified as CVE-2025-12469, is related to a missing authorization check. Simply put, the plugin isn’t properly verifying if a user has the necessary permissions to perform certain administrative tasks, specifically when sending test emails.

This oversight could allow an attacker with even basic authenticated access, like a subscriber, to send emails from your website, controlling both the subject and content. This could be misused for spamming, phishing attempts, or to spread misinformation, potentially harming your website’s reputation and your users.

CVE Details

  • Product: FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress
  • Published: November 5, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

This vulnerability affects all versions of the FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress up to, and including, version 3.6.4.1.

Current Status

This vulnerability has been analyzed and publicly disclosed, meaning information about it is available to the public.

Severity Level

Rated as Medium severity, this means the vulnerability could lead to unauthorized actions but might require specific conditions or lower-privileged access to be exploited. In this particular case, the issue stems from a combination of factors: a publicly exposed security token (nonce) and the plugin’s check_nonce() function accepting lower-privileged authenticated users. This means that a malicious actor, once logged in with a subscriber-level account or higher, could exploit this weakness to send emails with their own custom subject lines and body content directly from your WordPress installation. Such an attack could undermine trust in your communication channels and potentially impact your users.

Possible Solutions

To protect your WordPress site, it is crucial to update the FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin to a version greater than 3.6.4.1. This update addresses the missing authorization checks. Always ensure your plugins are kept up to date to receive the latest security patches and protect your website from known vulnerabilities.

References

https://plugins.trac.wordpress.org/browser/wp-marketing-automations/trunk/includes/abstracts/class-bwfan-ajax-controller.php#L296
https://plugins.trac.wordpress.org/browser/wp-marketing-automations/trunk/includes/class-bwfan-common.php#L1896
https://plugins.trac.wordpress.org/browser/wp-marketing-automations/trunk/includes/class-bwfan-public.php#L70
https://plugins.trac.wordpress.org/changeset/3388822/wp-marketing-automations/trunk/includes/abstracts/class-bwfan-ajax-controller.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/72198b74-90f6-49c6-b261-6f9c1cdc9692?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.