logo

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

ID: f8020dc5-d440-58f0-a311-91650f161058

STIX ID: report--f8020dc5-d440-58f0-a311-91650f161058

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: [email protected] (The Hacker News)

...
...

A critical vulnerability in the Funnel Builder WordPress plugin (affecting versions before 3.15.0.3) is being actively exploited to inject malicious JavaScript into WooCommerce checkout pages; attackers plant GTM-like scripts that load a payment skimmer via a WebSocket C2, stealing credit card numbers, CVVs, billing addresses and other checkout data. Site owners should update to version 3.15.0.3 and review Settings > Checkout > External Scripts for unfamiliar code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.