{
 "id": "WPSEC-2026-0696",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0696/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0696/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0696/index.md",
 "title": "FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.16.0.5 - Unauthenticated Stored Cross-Site Scripting via Order Received Page Tracking Data",
 "description": "The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purchase tracking data printed in inline scripts on the order received (Thank You) page in all versions up to, and including, 3.16.0.5. This is due to JSON-encoded order data, including customer-supplied shipping name, city, state, postcode and phone fields, being placed inside a single-quoted JavaScript string passed to JSON.parse() without escaping single quotes. This makes it possible for unauthenticated attackers to place an order with crafted customer details and inject arbitrary web scripts that execute in the browser of the first user who opens that order's received page, for example an administrator who follows a link to it.",
 "plugin": {
  "slug": "funnel-builder",
  "name": "FunnelKit – Funnel Builder for WooCommerce Checkout",
  "full_name": "FunnelKit – Funnel Builder for WooCommerce Checkout",
  "wordpress_org": "https://wordpress.org/plugins/funnel-builder/",
  "advisories_url": "https://wpsec.com/vuln/plugin/funnel-builder/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/funnel-builder"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "3.16.0.6",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 3.16.0.6"
  ]
 },
 "introduced_in": null,
 "fixed_in": "3.16.0.6",
 "remediation": "Update to 3.16.0.6 or later.",
 "fix_released": "2026-10-08T06:27:56+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:08.424264+00:00",
 "also_published_as": {
  "source": "wordfence",
  "cve": [
   "CVE-2026-100147"
  ],
  "published": "2026-10-09T19:41:06+00:00"
 },
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0696/",
  "https://plugins.svn.wordpress.org/funnel-builder/tags/3.16.0.6/",
  "https://wordpress.org/plugins/funnel-builder/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/funnel-builder",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-10"
 }
}