CVE-2025-10567: FunnelKit < 3.12.0.1 - Reflected XSS
Published Nov 5, 2025
·Updated
The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.
Affected Software
1 affected component
FunnelKit FunnelKit<3.12.0.1
Event History
Nov 5, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-10567?
CVE-2025-10567 is classified as a high severity vulnerability due to its potential for reflected XSS attacks against logged-in users.
2
How do I fix CVE-2025-10567?
To fix CVE-2025-10567, update the FunnelKit WordPress plugin to version 3.12.0.1 or later.
3
Who is affected by CVE-2025-10567?
CVE-2025-10567 affects users of the FunnelKit WordPress plugin versions prior to 3.12.0.1.
4
What type of attack is associated with CVE-2025-10567?
CVE-2025-10567 allows attackers to perform reflected XSS attacks targeting logged-in users.
5
What functionality of the FunnelKit plugin is impacted by CVE-2025-10567?
CVE-2025-10567 impacts some checkout-related AJAX actions, where user input is not properly sanitized.