CVE-2025-7654 is a Sensitive Information Exposure vulnerability affecting multiple FunnelKit plugins, specifically FunnelKit – Funnel Builder for WooCommerce Checkout and FunnelKit Automations. Authenticated attackers with Contributor-level access or higher can exploit a shortcode (wf_get_cookie) to extract sensitive data, including authentication cookies of other users, potentially leading to privilege escalation. This vulnerability carries a high CVSS score of 8.8, indicating a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Amans2k | FunnelKit Automations – Email Marketing Automation And CRM For WordPress & WooCommerce | >= 0, <= 3.6.3CNA affecteddefault unaffected | |
| Amans2k | FunnelKit – Funnel Builder For WooCommerce Checkout | >= 0, <= 3.11.0.2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.