ctipilot.ch
← Back to Weekly 2026-W20
NOTABLEexploitedsynthesis

WordPress retail / e-commerce

discovered 2026-05-11 05:00 UTCrun 2026-W20-71c96b252 sourcesmulti-source

FunnelKit "Funnel Builder for WooCommerce" actively exploited as a Magecart skimmer on 40,000+ WordPress stores (daily 2026-05-17), no CVE assigned. The operational pattern (Magecart abuse of a popular WooCommerce plugin) is portable across the WordPress + WooCommerce e-commerce ecosystem used by Swiss / EU SMB retailers; SOC managers serving SMB or municipal e-commerce estates should sweep deployed WooCommerce plugin inventories for the affected FunnelKit version and audit checkout-page DOM for injected payment-form-skimming scripts.

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.