PatchSiren

FunnelKit CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM FunnelKit CVE published 2026-07-16

CVE-2026-12979

The FunnelKit WordPress plugin before 3.15.0.6 has a path traversal vulnerability. Users with administrator privileges can delete arbitrary .json files outside the intended directory during a template-import operation. This vulnerability can potentially cause a denial of service. Administrators should review the official CVE record and NVD detail page for more information.

HIGH FunnelKit CVE published 2026-07-16

CVE-2026-12978

The FunnelKit WordPress plugin before 3.15.0.6 has a Reflected Cross-Site Scripting vulnerability. The plugin does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions. This allows unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered whe [truncated]

HIGH FunnelKit CVE published 2026-07-13

CVE-2026-57816

A Cross-site Scripting vulnerability was found in Funnel Builder by FunnelKit, a product used for building funnels. The vulnerability, tracked as CVE-2026-57816, is rated as HIGH with a CVSS score of 7.1. The affected versions are from n/a through <= 3.15.0.8. The CVE record was published on 2026-07-13T10:16:45.620Z and has not been modified since then. The NVD entry is currently Received. Administrators [truncated]

MEDIUM FunnelKit CVE published 2026-06-26

CVE-2026-57635

A medium severity Unauthenticated Cross Site Request Forgery (CSRF) vulnerability was discovered in the FunnelKit Payment Gateway for Stripe WooCommerce plugin, affecting versions up to 1.14.0.3. The vulnerability, tracked as CVE-2026-57635, has a CVSS score of 6.5. The issue was publicly disclosed on June 26, 2026, and the CVE record was last modified on June 29, 2026. The vulnerability allows an attacke [truncated]

HIGH FunnelKit CVE published 2026-06-15

CVE-2026-48966

CVE-2026-48966 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Funnel Builder by FunnelKit versions <= 3.15.0.2. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt]. The CVSS score is 7.1.

CRITICAL FunnelKit CVE published 2026-06-15

CVE-2026-42381

CVE-2026-42381 is a critical unauthenticated SQL injection vulnerability in Funnel Builder by FunnelKit versions <= 3.15.0.1. The vulnerability has a CVSS score of 9.3 and is considered critical. It was published on 2026-06-15T21:16:53.990Z and modified on 2026-06-15T21:24:32.790Z.

HIGH FunnelKit CVE published 2026-05-19

CVE-2026-47100

CVE-2026-47100 describes a missing-authorization flaw in Funnel Builder for WooCommerce Checkout versions before 3.15.0.3. An unauthenticated attacker can invoke internal methods through the public checkout endpoint and write arbitrary data to the plugin’s External Scripts global setting, creating a path to JavaScript injection on checkout pages.