Executive brief
Funnel Kit Funnel Builder PRO, a popular WordPress plugin used for creating sales funnels and marketing pages, contains a security vulnerability that could allow attackers to inject malicious scripts into the website. If an attacker successfully exploits this, they could redirect visitors to malicious sites, steal session information, or display unauthorized advertisements. This risk is particularly relevant for sites with customer accounts, as the attack can be initiated by users with low-level 'Customer' privileges.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Funnel Kit Funnel Builder PRO versions up to and including 3.15.0.4 due to improper neutralization of input during web page generation (CWE-79). The vulnerability requires 'Customer' level privileges (PR:L) and some degree of user interaction (UI:R) from a more privileged user, such as an administrator viewing a crafted page. Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 3.15.0.5.
Affected products
- Wisetr INC. Funnel Kit Funnel Builder PRO <= 3.15.0.4
Timeline
- 2026-05-13: other: Reported by Austin Ginder
- 2026-07-07: disclosed: Initial disclosure by Patchstack
- 2026-07-23: advisory: NVD publication date
- 2026-07-23: patched: Patch confirmed available in version 3.15.0.5