PricingCase studies Login Start trial
Plugin Icon

Funnelforms Free

N/A

Developer

N/A

Latest version

N/A

Installations

N/A

Last updated

WordPress Plugin
No VDP
Claim ownership
Report vulnerability
    VulnerabilitiesSecurity Contributors

Vulnerability history

3 present
9 patched
4 Mitigation rules
  • WordPress Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor - Funnelforms Free plugin <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Deletion vulnerability
    <= 3.7.3.2
    Feb 2, 2026
  • Cross Site Scripting (XSS) vulnerability
    <= 3.8
    Dec 31, 2025
  • Broken Access Control vulnerability
    <= 3.8
    Dec 25, 2025
  • Authenticated (Contributor+) PHP Object Injection vulnerability
    <= 3.7.5.1
    Dec 3, 2024
  • Missing Authorization to Unauthenticated Arbitrary Media Upload and Deletion vulnerability
    <= 3.7.3.2
    Aug 28, 2024
  • Authenticated (Administrator+) Arbitrary File Deletion vulnerability
    <= 3.7.3.2
    Aug 28, 2024
  • Authenticated (Administrator+) Arbitrary File Upload vulnerability
    <= 3.7.3.2
    Aug 28, 2024
  • Cross-Site Request Forgery to Arbitrary Post Duplication vulnerability
    <= 3.4
    Nov 2, 2023
  • Cross-Site Request Forgery to Arbitrary Post Deletion vulnerability
    <= 3.4
    Nov 2, 2023
  • Multiple Missing Authorization vulnerability
    <= 3.4
    Nov 2, 2023
  • Unauthenticated Stored Cross-Site Scripting vulnerability
    < 3.4
    Sep 19, 2023
  • WordPress Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor - Funnelforms Free plugin < 3.3.8.5 - Reflected Cross Site Scripting (XSS) vulnerability
    < 3.3.8.5
    Jul 18, 2023

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Documentation
  • Service status
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory 1,152
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Partners
  • Vulnerability database
  • Whitepaper 2026 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2026 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions