Attackers exploit Funnel Builder bug to inject e-skimmers into e-stores
ID: d976cb79-949b-5a7a-b578-1523c7c17e59
STIX ID: report--d976cb79-949b-5a7a-b578-1523c7c17e59
Feed Name: Security Affairs
Attackers are actively exploiting a critical unauthenticated flaw in the WordPress Funnel Builder (FunnelKit) plugin to modify the plugin’s External Scripts setting and inject fake Google Tag Manager/analytics scripts into WooCommerce checkout pages. The injected loader fetches a second-stage payment skimmer and opens a WebSocket to a remote C2 (wss://protect-wss.com/ws), allowing theft of credit card numbers, CVVs and billing details; FunnelKit released patch 3.15.0.3 and Sansec published IoCs and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
