Executive brief
Funnel Kit Funnel Builder PRO, a WordPress plugin used to create sales funnels and marketing pages, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks a specially crafted link, the attacker could potentially hijack sessions, redirect users to malicious websites, or deface the site. This vulnerability can be exploited by unauthenticated users, posing a risk to the site's reputation and user data.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Funnel Kit Funnel Builder PRO plugin for WordPress (versions 3.15.0.7 and below). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into interacting with a malicious link or form. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized actions. The issue is resolved in version 3.15.0.8.
Affected products
- Wisetr INC. Funnel Kit Funnel Builder PRO <= 3.15.0.7
Timeline
- 2026-05-26: disclosed: Reported by dutafi
- 2026-07-07: advisory: Patchstack advisory published
- 2026-07-23: advisory: NVD published date