SecAlerts
f

funnelkit

Security Risk Profile

44
/100
medium

Security Risk Score

Comprehensive risk assessment based on 33 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 22, 2022 to present

33
Total CVEs
16
Critical+High
1
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
44/100
medium
⚠️ 1 Active Exploits🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
15
Medium
16
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
11
2
SQL Injection
8
3
Infoleak
2
4
Path Traversal
1
5
CSRF
1

Most Affected Products

1. FunnelKit Funnelkit Automations Wordpress7
2. FunnelKit Funnel Builder Wordpress5
3. FunnelKit Funnel Builder by FunnelKit4
4. FunnelKit FunnelKit Automations4
5. FunnelKit Funnel Builder for WooCommerce Checkout3

Recent Vulnerabilities

See more →
CVE-2026-100147
CVSS 7.2high

FunnelKit <= 3.16.0.5 - Unauthenticated Stored Cross-Site Scripting via Order Fields (shipping/billing)

Oct 10, 2026🔧 No Patch
CVE-2026-12979
CVSS 5.5medium

FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer

Jul 16, 2026🔧 No Patch
CVE-2026-12978
CVSS 7.1high

FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form

Jul 16, 2026🔧 No Patch
CVE-2026-56052
CVSS 7.6high

WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.5 - SQL Injection vulnerability

Jun 24, 2026🔧 No Patch
CVE-2026-48966
CVSS 7.1high

WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.2 - Cross Site Scripting (XSS) vulnerability

Jun 15, 2026🔧 No Patch
CVE-2026-39450
CVSS 7.1high

WordPress FunnelKit Automations plugin <= 3.7.3 - Broken Authentication vulnerability

Jun 15, 2026🔧 No Patch
bleepingcomputer-20260515193033
unknown

Funnel Builder WordPress plugin bug exploited to steal credit cards

May 15, 2026⚠ Exploited🔧 No Patch
CVE-2025-66067
CVSS 6.5medium

WordPress Funnel Builder by FunnelKit plugin <= 3.13.1.2 - Cross Site Scripting (XSS) vulnerability

Nov 21, 2025🔧 No Patch
CVE-2025-12878
CVSS 6.4medium

FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.13.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wfop_phone Shortcode

Nov 19, 2025🔧 No Patch
CVE-2025-12469
CVSS 4.3medium

FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending

Nov 5, 2025

Monitor funnelkit in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

funnelkit Security Vulnerabilities & Risk Score | 33 CVEs | SecAlerts - SecAlerts