FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.16.0.5 - Unauthenticated Stored Cross-Site Scripting via Order Received Page Tracking Data
- ID
- WPSEC-2026-0696
- Plugin
- FunnelKit – Funnel Builder for WooCommerce Checkout (funnel-builder)
- Affected
- all versions before 3.16.0.6
- Remediation
- Update to 3.16.0.6 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
- Attack surface
- FunnelKit – Funnel Builder for WooCommerce Checkout on WPSec AttackSurface
- Fix released
- Published
Also published later by Wordfence as CVE-2026-100147, on 2026-10-09.
Description
The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purchase tracking data printed in inline scripts on the order received (Thank You) page in all versions up to, and including, 3.16.0.5. This is due to JSON-encoded order data, including customer-supplied shipping name, city, state, postcode and phone fields, being placed inside a single-quoted JavaScript string passed to JSON.parse() without escaping single quotes. This makes it possible for unauthenticated attackers to place an order with crafted customer details and inject arbitrary web scripts that execute in the browser of the first user who opens that order's received page, for example an administrator who follows a link to it.
References
- https://wpsec.com/vuln/WPSEC-2026-0696/
- https://plugins.svn.wordpress.org/funnel-builder/tags/3.16.0.6/
- https://wordpress.org/plugins/funnel-builder/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS