sansec.io
Funnel Builder Plugin Vulnerability Exploited in WooCommerce Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability in the Funnel Builder plugin for WooCommerce is being actively exploited, affecting over 40,000 websites. Attackers can inject malicious JavaScript into checkout pages without authentication, allowing them to steal sensitive customer payment data. The vulnerability exists in all versions prior to 3.15.0.3, which has been patched by FunnelKit. The malicious code masquerades as Google Tag Manager scripts, opening a WebSocket to an attacker-controlled server to deliver a payment skimmer. E-commerce security firm Sansec has confirmed ongoing exploitation and recommends immediate updates and scans for affected stores. Website owners are advised to check their plugin settings for unauthorized scripts. The vulnerability has not been assigned an official identifier yet.
Key Points: • Funnel Builder plugin vulnerability affects over 40,000 WooCommerce sites. • Attackers inject malicious JavaScript to steal payment data via unprotected endpoints. • FunnelKit released a patch for the vulnerability; immediate updates are recommended.