• News/
  • bleepingcomputer-20260515193033

Funnel Builder WordPress plugin bug exploited to steal credit cards

BleepingComputer
·
Bill Toulas
·
Published May 15, 2026
·
Updated

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. The flaw has not received an official identifier and can be leveraged without authentication. It affects all versions of the plugin before 3.15.0.3. Funnel Builder is a WordPress plugin for WooCommerce Checkout developed by FunnelKit, primarily used to customize checkout pages, with features like one-click upsells, landing pages, and to optimize conversion rates. Based on statistics from WordPress.org, the Funnel Builder plugin is active on more than 40,000 websites. E-commerce security company Sansec detected the malicious activity and noticed that the payload (analytics-reports[.]com/wss/jquery-lib.js) is disguised as a fake Google Tag Manager/Google Analytics script that opens a WebSocket connection to an external location (wss://protect-wss[.]com/ws). An attacker can exploit it to modify the plugin’s global settings via an unprotected, publicly exposed checkout endpoint. This allows them to inject arbitrary JavaScript into the plugin’s “External Scripts” setting, causing malicious code to execute on every checkout page. According to Sansec, the attacker-controlled server delivers a customized payment card skimmer that steals the following information: Payment card skimmers enable threat actors to make fraudulent online purchases, while stolen records often end up sold individually or in bulk on dark web p...

Read full article

Affected Software

1 affected component
FunnelKit Funnel Builder<3.15.0.3

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in the Funnel Builder WordPress plugin that can be exploited to inject malicious JavaScript into WooCommerce checkout pages.

2

What security implications are discussed?

The article highlights the risk of credit card theft due to the exploitation of this vulnerability.

3

What products or software are affected?

The affected software is the Funnel Builder plugin by FunnelKit, specifically versions up to 3.15.0.3.

4

How is the vulnerability being exploited?

Attackers are injecting malicious JavaScript snippets into the checkout pages of WooCommerce through this vulnerability.

5

Has this vulnerability been officially identified?

No, the flaw has not received an official identifier as of the publication of the article.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203