Executive brief
Funnel Builder by FunnelKit is a WordPress plugin used to create sales funnels and marketing automation workflows. A security vulnerability in this plugin could allow an administrative user to perform unauthorized database queries. This could lead to the exposure of sensitive customer information or internal site data, potentially impacting business operations and data privacy.
Technical details
A Blind SQL Injection vulnerability exists in the Funnel Builder by FunnelKit plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 3.15.0.5. An attacker with high privileges (such as an Administrator) can exploit this over the network without user interaction to extract sensitive information from the site's database. While the CVSS score is high (7.6) due to the potential for data exfiltration, the requirement for administrative privileges reduces the likelihood of exploitation by external actors. The issue is resolved in version 3.15.0.6.
Affected products
- FunnelKit Funnel Builder by FunnelKit n/a through 3.15.0.5
Timeline
- 2026-06-10: other: Reported by researcher Ananda Dhakal
- 2026-06-24: advisory: Public advisory published by Patchstack
- 2026-06-24: patched: Patch released in version 3.15.0.6