Thursday, October 8, 2026

Critical FunnelKit Vulnerability Puts 40,000+ WooCommerce Sites at Risk

A critical security vulnerability in the Funnel Builder plugin by FunnelKit is actively being exploited, putting more than 40,000 WooCommerce websites at risk of payment data theft.

The vulnerability affects all Funnel Builder versions prior to 3.15.0.3 and allows unauthenticated attackers to inject arbitrary JavaScript into WooCommerce checkout pages.

Funnel Builder is widely used to optimize checkout flows and upsell features, making it a high-value target for attackers seeking payment data at scale.

The issue stems from an insecure public checkout endpoint within the plugin. This endpoint allows incoming requests to specify which internal method should be executed.

However, affected versions fail to validate user permissions or restrict access to sensitive methods.

As a result, attackers can send crafted unauthenticated requests that directly invoke internal functions responsible for updating plugin settings.

This includes the “External Scripts” configuration, which is designed to allow administrators to add custom scripts such as analytics or tracking tools.

By abusing this functionality, attackers can insert malicious <script> tags that are automatically executed on every checkout page.

Security researchers at Sansec said in a report shared with GBhackers, have observed ongoing attacks where threat actors inject malicious scripts into checkout pages, silently harvesting sensitive customer information during transactions.

This effectively turns the checkout process into a data exfiltration point, exposing customers’ credit card numbers, CVVs, billing addresses, and other personal details.

FunnelKit addressed the issue in version 3.15.0.3 by implementing proper capability checks and restricting the endpoint to a safe list of allowed methods.

FunnelKit Vulnerability

Sansec reports that attackers are disguising their payloads as legitimate Google Tag Manager or analytics scripts a tactic commonly associated with Magecart-style campaigns.

These malicious scripts blend in with genuine tracking code, making them difficult to detect during routine inspections.

In one observed attack, the injected script uses base64 encoding to conceal a secondary payload URL. Upon page load, it decodes the string and loads an external script from a malicious domain:

  • Malicious domain: analytics-reports[.]com.
  • Payload delivery: /wss/jquery-lib.js.
  • Command-and-control (C2): wss://protect-wss[.]com/ws.

Once executed, the script establishes a WebSocket connection with the attacker’s infrastructure, dynamically retrieving a tailored payment skimmer. This skimmer intercepts and exfiltrates sensitive checkout data in real time.

This technique highlights a growing trend where attackers mimic trusted services like Google Analytics to evade detection, as administrators often overlook familiar-looking scripts.

Mitigations

FunnelKit has released a security patch and strongly urges all users to update immediately. Website administrators should take the following actions:

  • Update Funnel Builder to version 3.15.0.3 or later via the WordPress dashboard.
  • Review all entries under Settings > Checkout > External Scripts and remove any unfamiliar or suspicious code.
  • Scan the website using security tools such as Sansec’s eComscan to detect skimmers, backdoors, or other hidden threats.
  • Monitor checkout behavior and logs for unusual activity or unauthorized changes.

Given the active exploitation and the critical nature of the vulnerability, delaying updates could result in ongoing data theft and potential financial and reputational damage.

Organizations running WooCommerce stores should treat this issue as a high-priority incident and ensure immediate remediation to protect customer data and maintain trust.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

PoeLLM Malware Hijacks 3,400+ Servers for Crypto Mining and Botnet Expansion

A cryptocurrency mining campaign dubbed PoeLLM has compromised more...

Malicious npm Packages Steal Browser Passwords, Discord Tokens and Crypto Wallets.

MALFEX, a persistent npm supply-chain campaign distributing Windows malware...

Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands

Progress has disclosed a critical command injection vulnerability in...

Russian-Speaking CyberXero Uses AI Agent Swarm to Attack Ukrainian Energy Infrastructure

CyberXero, a Russian-speaking initial access broker combining conventional exploitation...

Hackers Use ERP Web Shell and IDOR Flaws to Breach Major South Korean Churches

Attackers breached two of South Korea’s largest churches through...

Related Articles

Recent News