Description
The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shipping_first_name' parameter in all versions up to, and including, 3.16.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Unauthenticated Stored Cross‑Site Scripting exploitation allows arbitrary code execution when users view injected order pages
Action: Immediate Patch
AI Analysis

Impact

The FunnelKit – Funnel Builder for WooCommerce Checkout plugin is vulnerable because the shipping_first_name parameter is not sanitized or escaped before being stored and rendered on thank‑you pages. A malicious actor can submit a crafted value that contains JavaScript or other code, which will be executed in the browsers of any visitor who views the affected order page. This can lead to theft of credentials, session hijacking, defacement, or the deployment of further malicious content. The flaw is a classic stored XSS weakness.

Affected Systems

All installations of FunnelKit – Funnel Builder for WooCommerce Checkout on WordPress that use version 3.16.0.5 or older are vulnerable. The plugin embeds the untrusted shipping field data in the HTML of thank‑you pages without proper sanitization. No patch version was listed for newer releases in the data, so the safe path is to upgrade if a newer version exists.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. Because the flaw is unauthenticated and does not require special privileges, the exploitation likelihood is high for sites that allow public or semi‑public order pages. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog. The attack vector is inferred to be remote via a public order or thank‑you page that renders the stored shipping data to any visitor.

Generated by OpenCVE AI on October 10, 2026 at 09:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FunnelKit to a version newer than 3.16.0.5 once available
  • Configure the plugin or use a custom filter to ensure that shipping and billing fields are properly escaped before output
  • Remove or disable untrusted fields from thank‑you pages until a patch is applied

Generated by OpenCVE AI on October 10, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shipping_first_name' parameter in all versions up to, and including, 3.16.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title FunnelKit <= 3.16.0.5 - Unauthenticated Stored Cross-Site Scripting via Order Fields (shipping/billing)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:43.163Z

Reserved: 2026-09-25T11:41:04.142Z

Link: CVE-2026-100147

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:02.930

Modified: 2026-10-10T08:17:02.930

Link: CVE-2026-100147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')