Briefing

Funnel Builder WordPress plugin bug exploited to steal credit cards

security
by Bill Toulas · WordPress WooCommerce

Patch: Update Funnel Builder to 3.15.0.3 immediately and remove any injected scripts from External Scripts settings.

What to do now

Patch: Upgrade Funnel Builder to 3.15.0.3 on all sites, audit External Scripts for malicious code, and monitor checkout logs for unusual WebSocket connections.

Summary

A critical vulnerability in the Funnel Builder plugin for WordPress, affecting all versions before 3.15.0.3, is actively exploited to inject malicious JavaScript into WooCommerce checkout pages. The flaw allows unauthenticated attackers to modify the plugin’s External Scripts setting, delivering a payload (analytics‑reports.com/wss/jquery‑lib.js) that masquerades as a Google Tag Manager script and opens a WebSocket to protect‑wss.com to skim credit card data. Sansec detected that the attacker‑controlled server steals credit card numbers, CVVs, billing addresses, and other customer information, and that the exploit is being used across more than 40,000 sites. FunnelKit released patch 3.15.0.3 yesterday, and the vendor advises site owners to update via the WordPress dashboard and review External Scripts for rogue code. The vulnerability was actively exploited before the patch, with no official CVE identifier yet. The flaw’s impact includes theft of payment card details and potential fraud or resale on dark‑web markets. The vendor’s advisory confirms the issue and recommends prioritizing the update. Site administrators should also audit checkout pages for unexpected WebSocket connections.

Key changes

  • Vulnerability allows unauthenticated injection of arbitrary JavaScript into WooCommerce checkout pages via the plugin’s External Scripts setting.
  • Affects all Funnel Builder plugin versions before 3.15.0.3.
  • Malicious payload (analytics‑reports.com/wss/jquery‑lib.js) opens a WebSocket to protect‑wss.com to skim credit card data.
  • Steals credit card numbers, CVVs, billing addresses, and other customer information.
  • Vendor released patch 3.15.0.3 to fix the issue.
  • Sansec advises updating via WordPress dashboard and reviewing External Scripts for rogue code.

Affects

wp-customers e-com-customers

Source angles · 2 perspectives

Bleeping Computer
Independent angle

Funnel Builder WordPress plugin bug exploited to steal credit cards

Open
The Hacker News
Independent angle

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting