← WordPress Vulnerabilities
WordPress security by component

Funnel Builder by FunnelKit

Funnel Builder by FunnelKit is a WordPress component with 16 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 9.3.

Plugin slug: funnel-builder

CVE-2026-57816: Funnel Builder by FunnelKit: Cross-site scripting

Funnel Builder by FunnelKit is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.15.0.8.

PublishedJul 13, 2026
Known safe version3.15.0.9
Safe version
Jul 13, 2026 CVE-2026-57816
Funnel Builder by FunnelKit: Cross-site scripting
Funnel Builder by FunnelKit is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.15.0.8.
3.15.0.9
CVE7.1
NVDPending
Jun 24, 2026 CVE-2026-56052
Funnel Builder by FunnelKit: SQL injection
Funnel Builder by FunnelKit is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 3.15.0.5.
3.15.0.6
CVE7.6
NVDPending
Jun 15, 2026 CVE-2026-48966
Funnel Builder by FunnelKit: Cross-site scripting
Funnel Builder by FunnelKit is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.15.0.2.
3.15.0.3
CVE7.1
NVDPending
Jun 15, 2026 CVE-2026-42381
Funnel Builder by FunnelKit: SQL injection
Funnel Builder by FunnelKit is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 3.15.0.1.
3.15.0.2
CVE9.3
NVDPending
Dec 12, 2025 CVE-2025-14169
FunnelKit - Funnel Builder for WooCommerce Checkout: SQL injection
FunnelKit - Funnel Builder for WooCommerce Checkout is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Nov 21, 2025 CVE-2025-66067
Funnel Builder by FunnelKit: Cross-site scripting
Funnel Builder by FunnelKit is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Nov 19, 2025 CVE-2025-12878
FunnelKit – Funnel Builder for WooCommerce Checkout: Cross-site scripting
FunnelKit – Funnel Builder for WooCommerce Checkout is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Aug 20, 2025 CVE-2025-54750
Funnel Builder by FunnelKit: Filesystem traversal
Funnel Builder by FunnelKit is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Aug 19, 2025 CVE-2025-7654
Funnel Builder: Privilege escalation or authentication bypass
Funnel Builder is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Jul 16, 2025 CVE-2025-49034
Funnel Builder by FunnelKit: SQL injection
Funnel Builder by FunnelKit is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
May 15, 2025 CVE-2025-2203
FunnelKit: SQL injection
FunnelKit is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.1
NVDPending
Feb 25, 2025 CVE-2025-26979
Funnel Builder by FunnelKit: Filesystem traversal
Funnel Builder by FunnelKit is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Aug 29, 2024 CVE-2024-1056
FunnelKit Funnel Builder Pro: Cross-site scripting
FunnelKit Funnel Builder Pro is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jul 24, 2024 CVE-2024-6836
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells: A security weakness
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jun 29, 2024 CVE-2024-5192
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells: Cross-site scripting
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 28, 2023 CVE-2023-50856
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize Profits: SQL injection
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize Profits is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2