Executive brief
FunnelKit is a popular WordPress plugin used to create sales funnels and checkout pages. A security flaw in its integration with the Divi page builder allows attackers to trick logged-in users, including administrators, into executing malicious scripts. If an administrator clicks a malicious link, an attacker could potentially take over the website or steal sensitive customer data.
Technical details
The FunnelKit plugin fails to sanitize the 'input_size' parameter within the 'et_wfop_optin_form' AJAX action before reflecting it into an HTML response. This action is registered when the Divi theme or builder is active and lacks proper nonce or capability checks. An attacker can craft a POST request (requiring 'et_load_builder_modules=1' to trigger the module load) that injects a script into a <style> block by closing the tag. When a logged-in user, such as an administrator, is induced to submit this request via a malicious page, the injected script executes in their browser session. This vulnerability was fixed in version 3.15.0.6.
Affected products
- FunnelKit FunnelKit Funnel Builder < 3.15.0.6
Timeline
- 2026-06-25: disclosed: Initial public disclosure by WPScan
- 2026-06-25: patched: Fixed in version 3.15.0.6
- 2026-07-16: advisory: CVE-2026-12978 published to NVD