PT-2026-41938 · WordPress · Funnelkit – Funnel Builder For Woocommerce Checkout

Published

2026-05-19

·

Updated

2026-05-30

·

CVE-2026-47100

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Funnel Builder for WooCommerce Checkout versions prior to 3.15.0.3
Description A missing authorization issue in the public checkout endpoint allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. This enables the injection of malicious JavaScript through the External Scripts setting, which then executes in the browsers of all visitors to the checkout page.
Recommendations Update to version 3.15.0.3 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-47100

Affected Products

Funnelkit – Funnel Builder For Woocommerce Checkout