Impact
The FunnelKit – Funnel Builder for WooCommerce Checkout plugin is vulnerable because the shipping_first_name parameter is not sanitized or escaped before being stored and rendered on thank‑you pages. A malicious actor can submit a crafted value that contains JavaScript or other code, which will be executed in the browsers of any visitor who views the affected order page. This can lead to theft of credentials, session hijacking, defacement, or the deployment of further malicious content. The flaw is a classic stored XSS weakness.
Affected Systems
All installations of FunnelKit – Funnel Builder for WooCommerce Checkout on WordPress that use version 3.16.0.5 or older are vulnerable. The plugin embeds the untrusted shipping field data in the HTML of thank‑you pages without proper sanitization. No patch version was listed for newer releases in the data, so the safe path is to upgrade if a newer version exists.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. Because the flaw is unauthenticated and does not require special privileges, the exploitation likelihood is high for sites that allow public or semi‑public order pages. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog. The attack vector is inferred to be remote via a public order or thank‑you page that renders the stored shipping data to any visitor.
OpenCVE Enrichment