Junglewise Threat Intelligence

CVE-2026-42381: FunnelKit Funnel Builder unauthenticated SQL injection

CVE-2026-42381 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Technologies: FunnelKit Funnel Builder. Vendors: FunnelKit.

Executive brief

Funnel Builder by FunnelKit, a popular WordPress plugin used to create sales funnels and marketing pages, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to interact directly with the website's database without needing a password. An exploit could lead to the theft of sensitive customer information, site data, or a complete compromise of the web server's database.

Technical details

An unauthenticated SQL injection vulnerability exists in the Funnel Builder by FunnelKit plugin for WordPress (versions up to and including 3.15.0.1). The flaw stems from improper neutralization of special elements used in an SQL command (CWE-89), allowing a remote attacker to send specially crafted requests to the application. Because the vulnerability requires no authentication or user interaction, it can be exploited over the network to extract sensitive data from the database or potentially gain further access to the environment. The issue is resolved in version 3.15.0.2.

Affected products

  • FunnelKit Funnel Builder by FunnelKit <= 3.15.0.1

Timeline

  • 2026-04-22: other: Reported by researcher daroo
  • 2026-04-27: advisory: Initial Patchstack advisory published
  • 2026-06-15: disclosed: CVE published to NVD

References

Related threats