Executive brief
Funnel Builder by FunnelKit, a popular WordPress plugin used to create sales funnels and marketing pages, contains a security flaw that allows unauthorized individuals to inject malicious scripts into the website. If a site administrator or visitor clicks a specially crafted link, an attacker could potentially hijack their session, redirect users to malicious websites, or deface the site. This vulnerability can be exploited without needing any login credentials, making it a significant risk for site owners.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Funnel Builder by FunnelKit plugin for WordPress (versions up to and including 3.15.0.2). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in session hijacking or unauthorized actions performed on behalf of a logged-in administrator. The issue is resolved in version 3.15.0.3.
Affected products
- FunnelKit Funnel Builder by FunnelKit <= 3.15.0.2
Timeline
- 2026-05-08: other: Reported by Tiago Ventura (@perses)
- 2026-06-03: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date