These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The FunnelKit WordPress plugin before 3.15.0.6 has a path traversal vulnerability. Users with administrator privileges can delete arbitrary .json files outside the intended directory during a template-import operation. This vulnerability can potentially cause a denial of service. Administrators should review the official CVE record and NVD detail page for more information.
The FunnelKit WordPress plugin before 3.15.0.6 has a Reflected Cross-Site Scripting vulnerability. The plugin does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions. This allows unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered whe [truncated]
A Cross-site Scripting vulnerability was found in Funnel Builder by FunnelKit, a product used for building funnels. The vulnerability, tracked as CVE-2026-57816, is rated as HIGH with a CVSS score of 7.1. The affected versions are from n/a through <= 3.15.0.8. The CVE record was published on 2026-07-13T10:16:45.620Z and has not been modified since then. The NVD entry is currently Received. Administrators [truncated]
A medium severity Unauthenticated Cross Site Request Forgery (CSRF) vulnerability was discovered in the FunnelKit Payment Gateway for Stripe WooCommerce plugin, affecting versions up to 1.14.0.3. The vulnerability, tracked as CVE-2026-57635, has a CVSS score of 6.5. The issue was publicly disclosed on June 26, 2026, and the CVE record was last modified on June 29, 2026. The vulnerability allows an attacke [truncated]
CVE-2026-48966 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Funnel Builder by FunnelKit versions <= 3.15.0.2. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt]. The CVSS score is 7.1.
CVE-2026-42381 is a critical unauthenticated SQL injection vulnerability in Funnel Builder by FunnelKit versions <= 3.15.0.1. The vulnerability has a CVSS score of 9.3 and is considered critical. It was published on 2026-06-15T21:16:53.990Z and modified on 2026-06-15T21:24:32.790Z.
CVE-2026-47100 describes a missing-authorization flaw in Funnel Builder for WooCommerce Checkout versions before 3.15.0.3. An unauthenticated attacker can invoke internal methods through the public checkout endpoint and write arbitrary data to the plugin’s External Scripts global setting, creating a path to JavaScript injection on checkout pages.