PatchSiren cyber security CVE debrief
CVE-2026-47100 FunnelKit CVE debrief
CVE-2026-47100 describes a missing-authorization flaw in Funnel Builder for WooCommerce Checkout versions before 3.15.0.3. An unauthenticated attacker can invoke internal methods through the public checkout endpoint and write arbitrary data to the plugin’s External Scripts global setting, creating a path to JavaScript injection on checkout pages.
- Vendor
- FunnelKit
- Product
- Funnel Builder for WooCommerce Checkout
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-07-24
Who should care
Site owners, WordPress administrators, and security teams running Funnel Builder for WooCommerce Checkout on public storefronts should treat this as urgent. Any environment exposing the affected plugin version before 3.15.0.3 may be at risk of checkout-page script injection affecting visitors.
Technical summary
The supplied CVE description and NVD metadata indicate a missing authorization weakness on a public checkout endpoint in Funnel Builder for WooCommerce Checkout prior to 3.15.0.3. The weakness is identified as CWE-862 in the source metadata. Because the endpoint is reachable without authentication, attackers can trigger internal functionality that updates the plugin’s External Scripts global setting. If malicious script content is stored there, it can execute in the browsers of checkout page visitors, which is consistent with a high-severity web injection impact. NVD lists the record as Deferred and includes references to the vendor fix in WordPress Trac, VulnCheck’s advisory, and Sansec research.
Defensive priority
High. This is unauthenticated, internet-reachable attack surface in a checkout path and can affect all visitors to impacted checkout pages until the plugin is updated and the injected setting is remediated.
Recommended defensive actions
- Update Funnel Builder for WooCommerce Checkout to version 3.15.0.3 or later as soon as possible.
- Review the plugin’s External Scripts global setting for unexpected or malicious content.
- Audit checkout-page assets and browser behavior for signs of injected JavaScript or unauthorized configuration changes.
- Check WordPress admin and application logs for unusual requests to the checkout endpoint before remediation.
- Verify all storefront instances, staging sites, and clones for affected plugin versions and inconsistent configuration drift.
Evidence notes
This debrief uses the supplied CVE description, publishedAt timestamp of 2026-05-19T15:16:32.117Z, and NVD metadata. NVD metadata classifies the issue as CWE-862 and lists references to the WordPress plugin Trac changeset for 3.15.0.3, VulnCheck’s advisory, and Sansec research. The NVD vulnStatus is Deferred in the supplied source item. No unsupported exploit details are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47100 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47100
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47100 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47100
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3530797/funnel-builder/tags/3.15.0.3/modules/checkouts/includes/class-wfacp-ajax-controller.php
-
Source reference
Unverified legacy reference
URL: https://sansec.io/research/funnelkit-woocommerce-vulnerability-exploited
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/funnel-builder-for-woocommerce-checkout-missing-authorization-via-ajax
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.