A critical security vulnerability in the Funnel Builder plugin by FunnelKit is actively being exploited, putting more than 40,000 WooCommerce websites at risk of payment data theft.
The vulnerability affects all Funnel Builder versions prior to 3.15.0.3 and allows unauthenticated attackers to inject arbitrary JavaScript into WooCommerce checkout pages.
Funnel Builder is widely used to optimize checkout flows and upsell features, making it a high-value target for attackers seeking payment data at scale.
The issue stems from an insecure public checkout endpoint within the plugin. This endpoint allows incoming requests to specify which internal method should be executed.
However, affected versions fail to validate user permissions or restrict access to sensitive methods.
As a result, attackers can send crafted unauthenticated requests that directly invoke internal functions responsible for updating plugin settings.
This includes the “External Scripts” configuration, which is designed to allow administrators to add custom scripts such as analytics or tracking tools.
By abusing this functionality, attackers can insert malicious <script> tags that are automatically executed on every checkout page.
Security researchers at Sansec said in a report shared with GBhackers, have observed ongoing attacks where threat actors inject malicious scripts into checkout pages, silently harvesting sensitive customer information during transactions.
This effectively turns the checkout process into a data exfiltration point, exposing customers’ credit card numbers, CVVs, billing addresses, and other personal details.
FunnelKit addressed the issue in version 3.15.0.3 by implementing proper capability checks and restricting the endpoint to a safe list of allowed methods.
FunnelKit Vulnerability
Sansec reports that attackers are disguising their payloads as legitimate Google Tag Manager or analytics scripts a tactic commonly associated with Magecart-style campaigns.
These malicious scripts blend in with genuine tracking code, making them difficult to detect during routine inspections.
In one observed attack, the injected script uses base64 encoding to conceal a secondary payload URL. Upon page load, it decodes the string and loads an external script from a malicious domain:
- Malicious domain: analytics-reports[.]com.
- Payload delivery: /wss/jquery-lib.js.
- Command-and-control (C2): wss://protect-wss[.]com/ws.
Once executed, the script establishes a WebSocket connection with the attacker’s infrastructure, dynamically retrieving a tailored payment skimmer. This skimmer intercepts and exfiltrates sensitive checkout data in real time.
This technique highlights a growing trend where attackers mimic trusted services like Google Analytics to evade detection, as administrators often overlook familiar-looking scripts.
Mitigations
FunnelKit has released a security patch and strongly urges all users to update immediately. Website administrators should take the following actions:
- Update Funnel Builder to version 3.15.0.3 or later via the WordPress dashboard.
- Review all entries under Settings > Checkout > External Scripts and remove any unfamiliar or suspicious code.
- Scan the website using security tools such as Sansec’s eComscan to detect skimmers, backdoors, or other hidden threats.
- Monitor checkout behavior and logs for unusual activity or unauthorized changes.
Given the active exploitation and the critical nature of the vulnerability, delaying updates could result in ongoing data theft and potential financial and reputational damage.
Organizations running WooCommerce stores should treat this issue as a high-priority incident and ensure immediate remediation to protect customer data and maintain trust.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





