CVE-2025-66067: WordPress Funnel Builder by FunnelKit plugin <= 3.13.1.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder allows DOM-Based XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.13.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66067?
CVE-2025-66067 is a medium severity vulnerability involving DOM-Based XSS that can lead to unauthorized script execution in affected software.
How do I fix CVE-2025-66067?
To fix CVE-2025-66067, update FunnelKit Funnel Builder or WordPress Funnel Builder to the latest version that exceeds 3.13.1.2.
Which versions of Funnel Builder are affected by CVE-2025-66067?
CVE-2025-66067 affects Funnel Builder by FunnelKit versions up to and including 3.13.1.2.
What type of vulnerability is CVE-2025-66067?
CVE-2025-66067 is identified as a Cross-site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation.
Is CVE-2025-66067 exploitable in production environments?
Yes, CVE-2025-66067 is potentially exploitable in production environments where the affected versions are deployed.