Funnel Builder WordPress plugin unauthenticated checkout script injection actively exploited security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Funnel Builder for WordPress has an actively exploited unauthenticated script-injection flaw that can compromise WooCommerce checkout pages and steal payment data. The issue affects versions before 3.15.0.3 and creates risk for the plugin’s more than 40,000 websites. Attackers can inject malicious JavaScript into the plugin’s External Scripts setting, turning checkout pages into skimming points. The flaw was fixed in 3.15.0.3.
Related Happenings
Funnel Builder plugin WordPress arbitrary JavaScript injection actively exploited security flaw
Vulnerability
H score72
First: 16.05.2026 18:20
Last: 16.05.2026 18:20
Sources 1
About this happening:
Funnel Builder for WordPress is under active exploitation for arbitrary JavaScript injection into WooCommerce checkout pages, creating payment-skimming risk across...
Funnel Builder plugin WordPress arbitrary JavaScript injection actively exploited security flaw
VulnerabilityAbout this happening: Funnel Builder for WordPress is under active exploitation for arbitrary JavaScript injection into WooCommerce checkout pages, creating payment-skimming risk across...
Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw
Vulnerability
H score30
First: 19.03.2026 22:01
Last: 19.03.2026 22:01
Sources 1
About this happening:
PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...
Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw
VulnerabilityAbout this happening: PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...
Stripe iframe skimmer campaign targeting merchants
Campaign
H score25
First: 24.09.2025 14:03
Last: 24.09.2025 14:03
Sources 1
About this happening:
The Stripe iframe skimmer campaign used malicious overlays to steal card data from dozens of merchants, raising checkout-fraud risk across payment pages. In August 2...
Stripe iframe skimmer campaign targeting merchants
CampaignAbout this happening: The Stripe iframe skimmer campaign used malicious overlays to steal card data from dozens of merchants, raising checkout-fraud risk across payment pages. In August 2...
Payment iframe defense against malicious overlays on checkout pages
Defensive Guidance
H score20
First: 24.09.2025 14:03
Last: 24.09.2025 14:03
Sources 1
About this happening:
Attackers are actively abusing payment iframes on checkout pages with malicious overlays, making strict CSP and real-time monitoring essential to prevent card...
Payment iframe defense against malicious overlays on checkout pages
Defensive GuidanceAbout this happening: Attackers are actively abusing payment iframes on checkout pages with malicious overlays, making strict CSP and real-time monitoring essential to prevent card...
Timeline
-
15.05.2026 22:30 1 articles · 2mo ago
Funnel Builder 3.15.0.3 patch released
Mitigation Patch UpdateFunnelKit released Funnel Builder version 3.15.0.3 to address the script-injection flaw affecting all versions before 3.15.0.3, providing a fix for the vulnerable WooCommerce checkout customization plugin.
Show sources
- Funnel Builder WordPress plugin bug exploited to steal credit cards — www.bleepingcomputer.com — 15.05.2026 22:30
-
15.05.2026 22:30 2 articles · 2mo ago
Active exploitation of Funnel Builder checkout script injection disclosed
Initial DisclosureSansec detected active exploitation of a critical unauthenticated Funnel Builder flaw that lets an attacker modify the plugin’s global settings through an unprotected checkout endpoint and inject malicious JavaScript into WooCommerce checkout pages. The payload is disguised as a fake Google Tag Manager/Google Analytics script, loads analytics-reports[.]com/wss/jquery-lib.js, opens a WebSocket connection to wss://protect-wss[.]com/ws, and delivers a customized payment card skimmer that can steal credit card numbers, CVVs, billing addresses, and other customer information from affected checkout flows.
Show sources
- Funnel Builder WordPress plugin bug exploited to steal credit cards — www.bleepingcomputer.com — 15.05.2026 22:30
- Funnel Builder WordPress plugin bug exploited to steal credit cards — www.bleepingcomputer.com — 15.05.2026 22:30