Funnel Builder Plugin Vulnerability Exploited in WooCommerce Attacks

Funnel Builder Plugin Vulnerability Exploited in WooCommerce Attacks

First seen 15 May 2026, 19:54 UTC Bleepingcomputersansec.ioScworldSecurityaffairs.CoForo3D 85% similarity 72.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability in the Funnel Builder plugin for WooCommerce is being actively exploited, affecting over 40,000 websites. Attackers can inject malicious JavaScript into checkout pages without authentication, allowing them to steal sensitive customer payment data. The vulnerability exists in all versions prior to 3.15.0.3, which has been patched by FunnelKit. The malicious code masquerades as Google Tag Manager scripts, opening a WebSocket to an attacker-controlled server to deliver a payment skimmer. E-commerce security firm Sansec has confirmed ongoing exploitation and recommends immediate updates and scans for affected stores. Website owners are advised to check their plugin settings for unauthorized scripts. The vulnerability has not been assigned an official identifier yet.

Key Points: • Funnel Builder plugin vulnerability affects over 40,000 WooCommerce sites. • Attackers inject malicious JavaScript to steal payment data via unprotected endpoints. • FunnelKit released a patch for the vulnerability; immediate updates are recommended.

ThreatCluster AI

Timeline

2026-05-14
Patch released for Funnel Builder plugin
FunnelKit released version 3.15.0.3 to fix the critical vulnerability allowing script injection.
Bleepingcomputer
2026-05-15
Sansec detects active exploitation
Sansec reported ongoing attacks exploiting the Funnel Builder vulnerability to inject malicious scripts.
sansec.io

Community

Browse all →