CVE-2026-48966: WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.2 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Funnel Builder by FunnelKit Pluginto a version that resolves this vulnerability.Fixed in 3.15.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48966?
CVE-2026-48966 has a severity rating of 7.1, categorized as high.
How do I fix CVE-2026-48966?
To remediate CVE-2026-48966, update the Funnel Builder by FunnelKit plugin to version 3.15.0.3 or later.
What kind of vulnerability is CVE-2026-48966?
CVE-2026-48966 is a Cross Site Scripting (XSS) vulnerability that affects versions of the Funnel Builder by FunnelKit plugin up to 3.15.0.2.
What are the potential impacts of CVE-2026-48966?
Exploitation of CVE-2026-48966 could allow an attacker to execute arbitrary scripts in the context of the affected site.
Who is affected by CVE-2026-48966?
Anyone using Funnel Builder by FunnelKit plugin versions 3.15.0.2 or earlier is at risk from CVE-2026-48966.