Skip to content
TrustYourWebsite
What We CheckFree ToolsLearnPricingAbout
Menu
What We CheckFree ToolsLearnPricingAboutSample ReportNews

Settings

Country

Scan Free
TrustYourWebsite

Intelligent scanner for European websites.

Resources

  • Learning Hub
  • Guides
  • By Industry
  • By Country
  • News
  • Cookie Checker
  • Privacy Policy Generator

Product

  • Pricing
  • Sample Report
  • About
  • Open source

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Imprint
  • Report accessibility issue

© 2026 TrustYourWebsite. Built in the Netherlands. Chamber of Commerce (NL): 42030553 · VAT: NL005443213B36

Supervisory authority: Data Protection Commission (DPC) · AP (NL) as lead supervisory authority

Digital service, available immediately after payment. No shipping costs.

Home/News/FunnelKit Plugin Vulnerability Steals Payment Data
Security

FunnelKit Plugin Vulnerability Steals Payment Data

By Steven | TrustYourWebsite29 May 20262 min read

Source: BleepingComputer

A serious security vulnerability in the FunnelKit Funnel Builder plugin for WordPress is reportedly being actively exploited by attackers to steal payment card information from customers at checkout. According to BleepingComputer, the flaw affects all versions of the plugin before 3.15.0.3 and can be exploited without any login or authentication.

What is happening?

According to BleepingComputer, attackers are targeting an unprotected checkout endpoint in the plugin. This allows them to change the plugin's global settings without needing a password or account. Once inside, they inject malicious JavaScript code into a setting called "External Scripts," which then runs on every checkout page your customers visit.

The injected code is reportedly disguised as a fake Google Tag Manager or Google Analytics script, making it hard to spot. It opens a hidden connection to an external server and delivers a payment card skimmer, a piece of code designed to silently copy sensitive information as customers type it in. According to BleepingComputer, the stolen data can include credit card numbers, CVVs, billing addresses and other customer information.

The plugin is reportedly active on more than 40,000 websites, according to BleepingComputer.

What has FunnelKit done?

FunnelKit has released version 3.15.0.3 of the Funnel Builder plugin to fix the vulnerability. The company recommends that website owners update to this version immediately through the WordPress dashboard. FunnelKit also advises checking Settings > Checkout > External Scripts to look for any suspicious scripts an attacker may have already added.

It is worth noting that this reporting comes from BleepingComputer, a secondary news source, rather than a direct vendor advisory or official regulatory decision. The vulnerability has not received an official CVE identifier, according to BleepingComputer.

Steps to take now

If you use the FunnelKit Funnel Builder plugin on your WooCommerce store, here is what to do:

  • Update immediately to version 3.15.0.3 or later via your WordPress dashboard
  • Check your External Scripts setting under Settings > Checkout > External Scripts and remove anything unfamiliar
  • Review your site against our security checklist for small businesses
  • Read more about keeping WordPress plugins safe

What does this mean for your website?

If you run an online shop using WooCommerce and the FunnelKit Funnel Builder plugin, your customers' payment details could be at risk if you have not yet updated. Updating your plugins promptly is one of the most straightforward ways to protect your customers and your business. Even if you are unsure whether your site is affected, checking the External Scripts setting costs nothing and takes only a few minutes.

Share this article

Check your website now

Free website scan covering GDPR, copyright, accessibility, security, and more.

Start free check

Related articles

Security

Exim CVE-2026-45185: Remote Code Execution Flaw Fixed

A critical use-after-free vulnerability (CVE-2026-45185) in Exim's GnuTLS backend allows unauthenticated remote code execution on mail servers, fixed in version 4.99.3.

29 May 20262 min read
Security

Avada Builder Vulnerabilities: Update to Version 3.15.3 Now

Two vulnerabilities in the Avada Builder WordPress plugin (CVE-2026-4782 and CVE-2026-4798) allow arbitrary file read and SQL injection attacks, enabling credential theft and potential site takeover.

29 May 20262 min read
Security

TanStack npm Hack: 84 Malicious Packages Released

An attacker published 84 malicious versions of official TanStack npm packages between 19:20 and 19:26 UTC on May 11, 2026, delivering credential theft, self-propagation, and disk-wiping malware via a…

28 May 20262 min read