FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.16.0.5 - Unauthenticated Stored Cross-Site Scripting via Order Received Page Tracking Data

Medium 4.7 CWE-79Fixed in 3.16.0.6
ID
WPSEC-2026-0696
Plugin
FunnelKit – Funnel Builder for WooCommerce Checkout (funnel-builder)
Affected
all versions before 3.16.0.6
Remediation
Update to 3.16.0.6 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
Attack surface
FunnelKit – Funnel Builder for WooCommerce Checkout on WPSec AttackSurface
Fix released
Published

Also published later by Wordfence as CVE-2026-100147, on 2026-10-09.

Description

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purchase tracking data printed in inline scripts on the order received (Thank You) page in all versions up to, and including, 3.16.0.5. This is due to JSON-encoded order data, including customer-supplied shipping name, city, state, postcode and phone fields, being placed inside a single-quoted JavaScript string passed to JSON.parse() without escaping single quotes. This makes it possible for unauthenticated attackers to place an order with crafted customer details and inject arbitrary web scripts that execute in the browser of the first user who opens that order's received page, for example an administrator who follows a link to it.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0