Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High1
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-07-24

CVE-2026-47100 - Funnel Builder for WooCommerce Checkout Plugin

Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.

PLUGIN Funnel Builder for WooCommerce Checkout

CVE-2026-47100

HIGH CVSS 8.7 2026-05-19
Threat Entry Updated 2025-11-19

CVE-2025-12878 - Funnel Builder For Woocommerce Checkout Plugin

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wfop_phone` shortcode in all versions up to, and including, 3.13.1.2. This is due to insufficient input sanitization and output escaping on the user-supplied `default` attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Funnel Builder For Woocommerce Checkout

CVE-2025-12878

MEDIUM CVSS 6.4 2025-11-19
Scroll to top