logo

Funnel Builder WordPress plugin bug exploited to steal credit cards

ID: c7cce5a7-6819-5050-b87d-536473cd391e

STIX ID: report--c7cce5a7-6819-5050-b87d-536473cd391e

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Bill Toulas

...
...

A critical unauthenticated vulnerability in the Funnel Builder (FunnelKit) WordPress plugin (affecting versions before 3.15.0.3) is being actively exploited to inject a fake Google Tag Manager/Analytics script (analytics-reports.com/wss/jquery-lib.js) into WooCommerce checkout pages; the malicious script opens a WebSocket (wss://protect-wss.com/ws) and delivers a payment-card skimmer that steals card numbers, CVVs, billing addresses and other customer data. FunnelKit released version 3.15.0.3 to address the issue and recommends updating and checking Settings > Checkout > External Scripts for rogue entries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.