---
schema: 1
kind: incident
title: "FunnelKit \"Funnel Builder for WooCommerce\" actively exploited as Magecart skimmer on 40,000+ WordPress stores — no CVE assigned"
headline: "FunnelKit \"Funnel Builder for WooCommerce\" actively exploited as Magecart skimmer on 40,000+ WordPress stores — no CVE assigned"
summary: "FunnelKit \"Funnel Builder for WooCommerce\" actively exploited as Magecart skimmer on 40,000+ WordPress checkout pages — no CVE assigned. Unauthenticated POST to an internal-method dispatcher writes attacker-controlled JavaScript into the plugin's External Scripts setting; a fake Google Tag Manager loader opens a WebSocket to attacker C2 and pulls a storefront-tailored card skimmer. Patched in v3.15.0.3 (Sansec, 2026-05-14)."
discovered_at: "2026-05-17T05:00:01Z"
event_date: 2026-05-16
run_id: 2026-05-17-4381863a
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - rce
  - supply-chain
  - data-breach
  - patch-available
regions:
  - global
sectors:
  - retail
  - healthcare
  - public-sector
  - education
entities:
  - "campaign:funnelkit-funnel-builder-for-woocommerce-actively-exploited-magecart-skimmer"
cves: []
sources:
  - url: "https://sansec.io/research/funnelkit-woocommerce-vulnerability-exploited"
    publisher: "Sansec, 2026-05-14"
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards/"
    publisher: "BleepingComputer, 2026-05-15"
    role: corroborating
  - url: "https://thehackernews.com/2026/05/funnel-builder-flaw-under-active.html"
    publisher: "The Hacker News, 2026-05-16"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Funnel Builder includes a publicly exposed checkout endpoint that allows an incoming request to choose the type of internal method to run. In at least one case, Sansec observed a payload masquerading as a Google Tag Manager (GTM) loader to launch JavaScript hosted on a remote domain. It subsequently opens a WebSocket connection to the attacker's command-and-control (C2) server to retrieve a skimmer that's tailored to the victim's storefront."
    publisher: The Hacker News citing Sansec
  - quote: "The vulnerability currently does not have an official CVE identifier. It affects all versions of the plugin before v3.15.0.3 and is used in more than 40,000 WooCommerce stores."
    publisher: The Hacker News
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch FunnelKit Funnel Builder for WooCommerce to v3.15.0.3+ immediately on any operator-managed WordPress instance** and manually purge `Settings > Checkout > External Scripts`. Active exploitation across 40,000+ stores via unauthenticated checkout-endpoint injection; the WebSocket-fed skimmer is polymorphic per victim and will not be caught by static IOC matches. Reference: § 1 FunnelKit item."
migrated_from: briefs/2026-05-17.md
---

Sansec published primary research on 2026-05-14 documenting active exploitation of an unauthenticated code-injection flaw in FunnelKit's Funnel Builder for WooCommerce plugin, with BleepingComputer corroborating on 2026-05-15 and The Hacker News expanding on 2026-05-16 ([Sansec, 2026-05-14](https://sansec.io/research/funnelkit-woocommerce-vulnerability-exploited); [BleepingComputer, 2026-05-15](https://www.bleepingcomputer.com/news/security/funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards/); [The Hacker News, 2026-05-16](https://thehackernews.com/2026/05/funnel-builder-flaw-under-active.html)). The vulnerable component is a publicly-exposed POST endpoint for checkout-funnel session management that fails to validate caller permissions — per The Hacker News's coverage of Sansec's research, *"Funnel Builder includes a publicly exposed checkout endpoint that allows an incoming request to choose the type of internal method to run"*. An unauthenticated request can invoke the internal method responsible for writing the plugin's global settings and inject arbitrary content into the `External Scripts` field (Settings > Checkout > External Scripts), which then executes on every checkout page site-wide. Mapped to `T1190` Exploit Public-Facing Application + `T1505.003` Web-Shell-equivalent (Magecart variant). Sansec observed the live payload masquerading as a Google Tag Manager initialiser; the fake GTM loader pulls JavaScript from an attacker-controlled domain, opens a WebSocket to attacker C2, and retrieves a storefront-tailored skimmer that harvests credit-card numbers, CVVs, and billing data in real time during checkout. No CVE has been assigned. Affected: all FunnelKit Funnel Builder for WooCommerce versions before v3.15.0.3. **Why it matters to us:** the unauthenticated-write-to-plugin-settings pattern is increasingly common across WordPress commerce plugins and is reachable by any internet scanner — Swiss/EU cantonal e-service portals, healthcare patient-payment systems, and university e-commerce instances running WooCommerce are exposed without operator action. The WebSocket-to-attacker-C2 channel makes the skimmer payload polymorphic per victim, so static-IOC scanning of checkout HTML will miss it; defenders should audit `wp_options` for unrecognised `funnel-builder` external-script entries and alert on any WebSocket (`wss://`) connection initiated from a WordPress PHP process or visible in browser checkout traffic to non-CDN endpoints. Hardening: update to v3.15.0.3+ immediately; manually purge the External Scripts setting; deploy a server-side malware scanner against the plugin install path. Three independent corroborating sources clear the SINGLE-SOURCE rule.
