logo

Critical FunnelKit Bug Leaves WooCommerce Stores Open To Attacks

ID: 996a3823-9518-5bd4-9de7-9967c671d356

STIX ID: report--996a3823-9518-5bd4-9de7-9967c671d356

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Varshini

...
...

A critical unauthenticated remote code-injection vulnerability in the Funnel Builder (FunnelKit) plugin (affecting versions before 3.15.0.3) enables attackers to write malicious entries to the plugin's External Scripts setting so injected scripts run on every checkout page; threat actors are actively exploiting the flaw to deploy disguised payment skimmers across an estimated 40,000+ WooCommerce stores. Administrators are advised to update the plugin, manually inspect Settings → Checkout → External Scripts for unfamiliar code, and run ecommerce malware scanners. Notable IOCs provided include analytics-reports.com/wss/jquery-lib.js and wss://protect-wss.com/ws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.