
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39440 is a critical code injection vulnerability in the FunnelFormsPro WordPress plugin by Funnelforms LLC that allows authenticated attackers with low privileges to perform Remote Code Inclusion (RCI). It affects FunnelFormsPro versions up to and including 3.8.1. The vulnerability was reported by researcher 3ele / Sebastian Weiss on January 25, 2026, and publicly disclosed on April 21–23, 2026. It carries a CVSS v3.1 base score of 9.9 (Critical) (Patchstack, Github Advisory).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), where the plugin constructs or evaluates code segments using externally-influenced input without properly neutralizing special elements that could alter code behavior. This allows an attacker to supply a malicious payload that causes the server to include and execute remote code. Exploitation requires only a low-privilege authenticated account (e.g., Subscriber level), no user interaction, and is network-accessible with low complexity. The attack scope is marked as "Changed," indicating that successful exploitation can impact resources beyond the vulnerable component itself (Patchstack, Github Advisory).
Successful exploitation grants an attacker the ability to execute arbitrary code on the underlying web server, resulting in high impact to confidentiality, integrity, and availability. An attacker could gain full backdoor access to the WordPress installation and the hosting environment, enabling data exfiltration, unauthorized content modification, installation of malware or web shells, and potential lateral movement to other systems on the same infrastructure. This vulnerability is considered suitable for mass-exploit campaigns targeting WordPress sites regardless of their size or traffic (Patchstack).
As of the time of disclosure, no public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation. However, Patchstack classifies this as high priority and notes that vulnerabilities of this severity are frequently used in mass-exploit campaigns. The EPSS score is approximately 0.017–0.022%, placing it in the 7th percentile for near-term exploitation probability. No CISA KEV catalog listing has been identified. Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts while an official patch is pending (Patchstack, Github Advisory).
include(), require(), or eval() with remote URLs.wp-content/plugins/funnelforms-pro/ directory or wp-content/uploads/; presence of web shells (e.g., files named shell.php, cmd.php, or obfuscated PHP files).php, curl, wget, bash) executing system commands; unexpected cron jobs or scheduled tasks added to the server.wp_options table).No official patch from Funnelforms LLC was available at the time of disclosure; the vulnerable version remains ≤ 3.8.1. Patchstack has issued a virtual patching rule that blocks exploitation attempts for sites protected by Patchstack. Recommended immediate actions include: (1) disabling or removing the FunnelFormsPro plugin until an official patch is released; (2) restricting plugin access to trusted, necessary users only and enforcing the principle of least privilege; (3) deploying a Web Application Firewall (WAF) capable of detecting and blocking code injection attempts; and (4) monitoring server logs and file system for signs of compromise. Check the WordPress plugin repository and vendor communications for patch availability (Patchstack).
Wordfence included CVE-2026-39440 in its weekly WordPress vulnerability report for the week of April 20–26, 2026, highlighting it as a notable critical issue (Wordfence Blog). The Hacker Wire covered the vulnerability with a dedicated article on the critical code injection flaw and also posted about it on Mastodon, contributing to broader community awareness. INCIBE (Spain's national cybersecurity agency) also published an early warning advisory for the vulnerability. General community sentiment reflects concern given the critical CVSS score and the absence of an official patch at time of disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."