CVE-2026-12979

FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer

The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3.15.0.6 or (denial of service).


We have discovered 217 live websites that are affected by CVE-2026-12979.

Run a Free Instant Scan




Affected Software

Product  Funnel Builder
Category Wordpress Plugins
Vulnerable Domains217 live websites (95% of Funnel Builder install base)
Vulnerable Versions
  • from 0 through 3.15.0.6
Vulnerable Versions Count14 versions ( 78% of all versions)


Common Weakness Enumeration

CWE-73 External Control of File Name or Path



Details

  • Published - Jul 16, 2026
  • Updated - Jul 16, 2026

Credits

  • Meher Sudhakar Abbireddi (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-12979
United States108 websites



France13 websites
Germany9 websites
GB8 websites
Netherlands8 websites
South Africa5 websites
Romania5 websites
Bulgaria5 websites
Poland5 websites
Cyprus5 websites

Website Distribution by TLD

Number of websites using CVE-2026-12979
.com136 websites
.nl7 websites
.co.uk6 websites
.fr6 websites
.org5 websites
.pl5 websites
.com.au3 websites
.it3 websites
.net2 websites
.co2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12979

Top websites that are affected by CVE-2026-12979. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.net United States***,***
*********.com United States***,***
***********.com United States***,***
*****************.com United States***,***
*************.com United States*,***,***
********************.com United States*,***,***
****************.pl Poland*,***,***
*****************.com United States*,***,***
*********.org United States*,***,***
***********.com United States*,***,***
See full domain list

FAQ

CVE-2026-12979 is External Control of File Name or Path in Funnel Builder
A total of 217 websites have been identified as vulnerable to CVE-2026-12979, based on global website indexing conducted by WebTechSurvey.
The Funnel Builder is affected by the CVE-2026-12979 vulnerability.
Funnel Builder versions up to 3.15.0.6 are vulnerable to CVE-2026-12979.
CVE-2026-12979 is resolved in version 3.15.0.6 of Funnel Builder.