Junglewise Threat Intelligence

CVE-2026-12978: FunnelKit WordPress plugin reflected XSS in Divi Optin Form

CVE-2026-12978 · Severity: info · CVSS 7.1 · Published 2026-07-16

Technologies: FunnelKit Funnel Builder for WooCommerce Checkout, FunnelKit Funnel Builder. Vendors: FunnelKit.

Executive brief

FunnelKit is a popular WordPress plugin used to create sales funnels and checkout pages. A security flaw in its integration with the Divi page builder allows attackers to trick logged-in users, including administrators, into executing malicious scripts. If an administrator clicks a malicious link, an attacker could potentially take over the website or steal sensitive customer data.

Technical details

The FunnelKit plugin fails to sanitize the 'input_size' parameter within the 'et_wfop_optin_form' AJAX action before reflecting it into an HTML response. This action is registered when the Divi theme or builder is active and lacks proper nonce or capability checks. An attacker can craft a POST request (requiring 'et_load_builder_modules=1' to trigger the module load) that injects a script into a <style> block by closing the tag. When a logged-in user, such as an administrator, is induced to submit this request via a malicious page, the injected script executes in their browser session. This vulnerability was fixed in version 3.15.0.6.

Affected products

  • FunnelKit FunnelKit Funnel Builder < 3.15.0.6

Timeline

  • 2026-06-25: disclosed: Initial public disclosure by WPScan
  • 2026-06-25: patched: Fixed in version 3.15.0.6
  • 2026-07-16: advisory: CVE-2026-12978 published to NVD

References

Related threats