# FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.16.0.5 - Unauthenticated Stored Cross-Site Scripting via Order Received Page Tracking Data

- **ID:** WPSEC-2026-0696
- **Plugin:** FunnelKit – Funnel Builder for WooCommerce Checkout (`funnel-builder`), https://wordpress.org/plugins/funnel-builder/
- **Affected versions:** all versions before 3.16.0.6
- **Fixed in:** 3.16.0.6 (Update to 3.16.0.6 or later.)
- **Severity:** Medium 4.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/funnel-builder
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0696/

## Description

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purchase tracking data printed in inline scripts on the order received (Thank You) page in all versions up to, and including, 3.16.0.5. This is due to JSON-encoded order data, including customer-supplied shipping name, city, state, postcode and phone fields, being placed inside a single-quoted JavaScript string passed to JSON.parse() without escaping single quotes. This makes it possible for unauthenticated attackers to place an order with crafted customer details and inject arbitrary web scripts that execute in the browser of the first user who opens that order's received page, for example an administrator who follows a link to it.

Also published later by wordfence as CVE-2026-100147.

## References

- https://wpsec.com/vuln/WPSEC-2026-0696/
- https://plugins.svn.wordpress.org/funnel-builder/tags/3.16.0.6/
- https://wordpress.org/plugins/funnel-builder/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0696/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
