Junglewise Threat Intelligence

CVE-2026-57816: FunnelKit Funnel Builder Reflected XSS

CVE-2026-57816 · Severity: high · CVSS 7.1 · Published 2026-07-13

Technologies: FunnelKit Funnel Builder. Vendors: FunnelKit.

Executive brief

Funnel Builder by FunnelKit is a WordPress plugin used to create sales funnels and marketing pages. A security vulnerability in this plugin allows attackers to inject malicious scripts into the website, which are then executed in the browser of other users. If a site administrator or customer clicks a specially crafted link, the attacker could potentially steal session information, redirect users to malicious sites, or perform unauthorized actions on their behalf.

Technical details

The Funnel Builder by FunnelKit plugin for WordPress (versions up to and including 3.15.0.8) is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on web page generation. An unauthenticated remote attacker can exploit this by tricking a user into clicking a crafted link or visiting a malicious page. The vulnerability is classified under CWE-79 and has a CVSS 3.1 base score of 7.1, as it requires user interaction but can lead to a full compromise of the user's browser session within the application's context. The issue is resolved in version 3.15.0.9.

Affected products

  • FunnelKit Funnel Builder by FunnelKit <= 3.15.0.8

Timeline

  • 2026-06-25: disclosed: Reported by daroo to Patchstack
  • 2026-07-10: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD record published
  • 2026-07-10: patched: Version 3.15.0.9 released to address the issue

References

Related threats