PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47100 FunnelKit CVE debrief

CVE-2026-47100 describes a missing-authorization flaw in Funnel Builder for WooCommerce Checkout versions before 3.15.0.3. An unauthenticated attacker can invoke internal methods through the public checkout endpoint and write arbitrary data to the plugin’s External Scripts global setting, creating a path to JavaScript injection on checkout pages.

Vendor
FunnelKit
Product
Funnel Builder for WooCommerce Checkout
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-19
Original CVE updated
2026-07-24
Advisory published
2026-05-19
Advisory updated
2026-07-24

Who should care

Site owners, WordPress administrators, and security teams running Funnel Builder for WooCommerce Checkout on public storefronts should treat this as urgent. Any environment exposing the affected plugin version before 3.15.0.3 may be at risk of checkout-page script injection affecting visitors.

Technical summary

The supplied CVE description and NVD metadata indicate a missing authorization weakness on a public checkout endpoint in Funnel Builder for WooCommerce Checkout prior to 3.15.0.3. The weakness is identified as CWE-862 in the source metadata. Because the endpoint is reachable without authentication, attackers can trigger internal functionality that updates the plugin’s External Scripts global setting. If malicious script content is stored there, it can execute in the browsers of checkout page visitors, which is consistent with a high-severity web injection impact. NVD lists the record as Deferred and includes references to the vendor fix in WordPress Trac, VulnCheck’s advisory, and Sansec research.

Defensive priority

High. This is unauthenticated, internet-reachable attack surface in a checkout path and can affect all visitors to impacted checkout pages until the plugin is updated and the injected setting is remediated.

Recommended defensive actions

  • Update Funnel Builder for WooCommerce Checkout to version 3.15.0.3 or later as soon as possible.
  • Review the plugin’s External Scripts global setting for unexpected or malicious content.
  • Audit checkout-page assets and browser behavior for signs of injected JavaScript or unauthorized configuration changes.
  • Check WordPress admin and application logs for unusual requests to the checkout endpoint before remediation.
  • Verify all storefront instances, staging sites, and clones for affected plugin versions and inconsistent configuration drift.

Evidence notes

This debrief uses the supplied CVE description, publishedAt timestamp of 2026-05-19T15:16:32.117Z, and NVD metadata. NVD metadata classifies the issue as CWE-862 and lists references to the WordPress plugin Trac changeset for 3.15.0.3, VulnCheck’s advisory, and Sansec research. The NVD vulnStatus is Deferred in the supplied source item. No unsupported exploit details are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47100 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47100

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47100 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47100

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/changeset/3530797/funnel-builder/tags/3.15.0.3/modules/checkouts/includes/class-wfacp-ajax-controller.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://sansec.io/research/funnelkit-woocommerce-vulnerability-exploited

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/funnel-builder-for-woocommerce-checkout-missing-authorization-via-ajax

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.