CVE-2026-56052: WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.5 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Blind SQL Injection.
This issue affects Funnel Builder by FunnelKit: from n/a through 3.15.0.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Funnel Builder by FunnelKit Pluginto a version that resolves this vulnerability.Fixed in 3.15.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56052?
CVE-2026-56052 has a severity score of 7.6, indicating it is considered high risk.
What does CVE-2026-56052 affect?
CVE-2026-56052 affects versions of the FunnelKit Funnel Builder plugin up to and including 3.15.0.5.
How do I fix CVE-2026-56052?
To fix CVE-2026-56052, update the FunnelKit Funnel Builder plugin to a version newer than 3.15.0.5.
What type of vulnerability is CVE-2026-56052?
CVE-2026-56052 is classified as an SQL Injection vulnerability.
What are the potential impacts of CVE-2026-56052?
CVE-2026-56052 can allow attackers to exploit blind SQL injection, potentially leading to data exposure or manipulation.