FunnelKit Automations Sensitive Information Exposure Vulnerability (CVE-2025-12468) — Medium Severity Explained

Understanding the FunnelKit Automations Coupon Data Exposure

A significant security flaw has been identified in the FunnelKit Automations plugin for WordPress, impacting all versions up to and including 3.6.4.1. This vulnerability, tracked as CVE-2025-12468, could allow unauthorized individuals to access sensitive WooCommerce coupon information, including coupon codes, their unique IDs, and expiration dates. This sensitive data exposure could be exploited by unauthenticated attackers, meaning they don’t need to log in to your WordPress site to get this information.

The core of the problem lies in a specific REST API endpoint, /wc-coupons/, which was mistakenly configured as a public API. This misconfiguration essentially bypasses all standard authentication and capability checks, making the coupon data readily available to anyone who knows where to look. For businesses relying on WooCommerce coupons for promotions and sales, this could lead to leaked discount codes, potentially impacting revenue or marketing campaigns.

CVE Details

This section provides specific technical details about the vulnerability:

  • Product: FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin
  • Published: November 5, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts the FunnelKit Automations plugin for WordPress. Specifically, all versions of the plugin up to, and including, 3.6.4.1 are susceptible to this information exposure. If you are using this plugin on your WordPress or WooCommerce site, it is crucial to verify your installed version.

Current Status

The vulnerability (CVE-2025-12468) has been “Analyzed.” This status indicates that the details of the flaw have been reviewed and categorized by security researchers. It’s a clear signal for users to take necessary precautions and monitor for official updates from the vendor.

Severity Level

CVE-2025-12468 has been assigned a Medium severity rating with a CVSS score of 5.3. A medium severity rating means that while the vulnerability may not allow for direct system control, it can still lead to significant negative impacts, such as the exposure of sensitive business data. In this case, the exposure of WooCommerce coupon codes could potentially be abused, leading to financial losses or compromised promotional campaigns. Understanding the severity helps you prioritize your security efforts. For more insights into safeguarding your online store, you might find our article on WooCommerce Security Best Practices helpful.

Possible Solutions

At the time of writing, the most critical step for users of the FunnelKit Automations plugin is to monitor for and apply security updates as soon as they become available. Given that the vulnerability lies in how an API endpoint is registered, a patch will likely involve correcting this configuration to properly enforce authentication and access controls. Ensure your WordPress installation, themes, and all plugins are kept up-to-date. Regularly check the official FunnelKit Automations plugin page on WordPress.org or their official website for announcements regarding security fixes. Implementing robust WordPress security best practices, such as using a web application firewall (WAF) and regularly auditing your site, can also provide an additional layer of defense against such vulnerabilities.

References

https://plugins.trac.wordpress.org/browser/wp-marketing-automations/trunk/includes/api/wc/class-bwfan-api-wc-coupons.php#L19

https://plugins.trac.wordpress.org/browser/wp-marketing-automations/trunk/includes/class-bwfan-api-loader.php#L119

https://www.wordfence.com/threat-intel/vulnerabilities/id/1d2a2032-3d39-4195-8e6c-ab884164721a?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.