CVE-2026-39440
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-39440 is a critical code injection vulnerability in the FunnelFormsPro WordPress plugin by Funnelforms LLC that allows authenticated attackers with low privileges to perform Remote Code Inclusion (RCI). It affects FunnelFormsPro versions up to and including 3.8.1. The vulnerability was reported by researcher 3ele / Sebastian Weiss on January 25, 2026, and publicly disclosed on April 21–23, 2026. It carries a CVSS v3.1 base score of 9.9 (Critical) (Patchstack, Github Advisory).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), where the plugin constructs or evaluates code segments using externally-influenced input without properly neutralizing special elements that could alter code behavior. This allows an attacker to supply a malicious payload that causes the server to include and execute remote code. Exploitation requires only a low-privilege authenticated account (e.g., Subscriber level), no user interaction, and is network-accessible with low complexity. The attack scope is marked as "Changed," indicating that successful exploitation can impact resources beyond the vulnerable component itself (Patchstack, Github Advisory).

Impact

Successful exploitation grants an attacker the ability to execute arbitrary code on the underlying web server, resulting in high impact to confidentiality, integrity, and availability. An attacker could gain full backdoor access to the WordPress installation and the hosting environment, enabling data exfiltration, unauthorized content modification, installation of malware or web shells, and potential lateral movement to other systems on the same infrastructure. This vulnerability is considered suitable for mass-exploit campaigns targeting WordPress sites regardless of their size or traffic (Patchstack).

Exploitability

As of the time of disclosure, no public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation. However, Patchstack classifies this as high priority and notes that vulnerabilities of this severity are frequently used in mass-exploit campaigns. The EPSS score is approximately 0.017–0.022%, placing it in the 7th percentile for near-term exploitation probability. No CISA KEV catalog listing has been identified. Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts while an official patch is pending (Patchstack, Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the FunnelFormsPro plugin version ≤ 3.8.1 using tools such as WPScan, Shodan, or by inspecting plugin directories on target sites.
  2. Obtain low-privilege account: Register or obtain credentials for a low-privilege WordPress account (e.g., Subscriber role) on the target site, as exploitation requires authentication at this level.
  3. Identify vulnerable input vector: Locate the FunnelFormsPro plugin functionality that accepts user-controlled input used in code generation or file inclusion logic (e.g., form configuration parameters or template fields).
  4. Craft malicious payload: Construct a Remote Code Inclusion payload — such as a URL pointing to an attacker-controlled PHP file or a code injection string — and submit it through the vulnerable plugin input.
  5. Trigger code execution: Submit the crafted request to the vulnerable endpoint, causing the server to include and execute the remote or injected code as the web server process.
  6. Establish persistence: Use the achieved code execution to deploy a web shell, create a backdoor admin account, or exfiltrate sensitive data from the WordPress database and file system (Patchstack, Github Advisory).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the web server to external/unknown IP addresses or domains (indicative of remote file inclusion); unusual DNS lookups originating from the web server process.
  • Logs: WordPress access logs showing POST requests to FunnelFormsPro plugin endpoints with unexpected URL-like or PHP code strings in parameters; PHP error logs referencing include(), require(), or eval() with remote URLs.
  • File System: Newly created or modified PHP files in the WordPress wp-content/plugins/funnelforms-pro/ directory or wp-content/uploads/; presence of web shells (e.g., files named shell.php, cmd.php, or obfuscated PHP files).
  • Process: Unusual child processes spawned by the web server (e.g., php, curl, wget, bash) executing system commands; unexpected cron jobs or scheduled tasks added to the server.
  • WordPress: New administrator accounts created without authorization; unexpected changes to WordPress options or plugin settings in the database (wp_options table).

Mitigation and workarounds

No official patch from Funnelforms LLC was available at the time of disclosure; the vulnerable version remains ≤ 3.8.1. Patchstack has issued a virtual patching rule that blocks exploitation attempts for sites protected by Patchstack. Recommended immediate actions include: (1) disabling or removing the FunnelFormsPro plugin until an official patch is released; (2) restricting plugin access to trusted, necessary users only and enforcing the principle of least privilege; (3) deploying a Web Application Firewall (WAF) capable of detecting and blocking code injection attempts; and (4) monitoring server logs and file system for signs of compromise. Check the WordPress plugin repository and vendor communications for patch availability (Patchstack).

Community reactions

Wordfence included CVE-2026-39440 in its weekly WordPress vulnerability report for the week of April 20–26, 2026, highlighting it as a notable critical issue (Wordfence Blog). The Hacker Wire covered the vulnerability with a dedicated article on the critical code injection flaw and also posted about it on Mastodon, contributing to broader community awareness. INCIBE (Spain's national cybersecurity agency) also published an early warning advisory for the vulnerability. General community sentiment reflects concern given the critical CVSS score and the absence of an official patch at time of disclosure.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92541HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-92540HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-86785MEDIUM5.3
  • woo-to-facebook-shop
NoNoSep 20, 2026
CVE-2026-92965LOW3.7
  • tiktok-for-business
NoYesSep 20, 2026
CVE-2026-92423LOW2.7
  • meow-gallery
NoYesSep 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management