Briefing

Critical Vulnerability in Funnel Builder Plugin Allows JS Injection into WooCommerce Checkout

security
by [email protected] (The Hacker News) · WordPress WooCommerce

Patch Funnel Builder immediately to stop malicious JavaScript injection into WooCommerce checkout pages.

What to do now

Patch Funnel Builder immediately to stop malicious JavaScript injection.

Summary

A critical security vulnerability affecting the Funnel Builder plugin for WordPress has been actively exploited in the wild. The flaw allows attackers to inject malicious JavaScript code into WooCommerce checkout pages. The injected script is designed to steal payment data from customers. The vulnerability has not yet been assigned an official CVE identifier. The attackers are using the flaw to compromise e‑commerce sites. The issue is being reported by Sansec. The plugin is widely used in WordPress‑based e‑commerce sites. The flaw is considered high risk.

The vulnerability is due to insufficient input sanitization in the plugin’s checkout integration. The attackers can bypass the checkout flow and capture card details. The issue is not limited to a specific version of Funnel Builder. The plugin developers have not released a patch yet. Site owners should check the plugin version. The vulnerability is actively exploited. The issue underscores the importance of secure plugin development. The attackers are targeting high‑value e‑commerce sites.

Key changes

  • Funnel Builder plugin for WordPress has a critical vulnerability that injects malicious JavaScript into WooCommerce checkout pages.
  • The flaw is actively exploited in the wild to steal payment data.
  • No official CVE identifier has been assigned yet.
  • The vulnerability is due to insufficient input sanitization in the plugin’s checkout integration.
  • Site owners should check the plugin version and apply a patch once available.

Affects

wp-customers e-com-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting