Impact
The FunnelKit WordPress plugin before version 3.15.0.6 fails to escape user‑supplied input before echoing it into its AJAX response, allowing an attacker to inject arbitrary HTML or JavaScript. This results in reflected cross‑site scripting against authenticated users who load a crafted page. If the injected script executes, attackers can steal session cookies, hijack accounts, or launch further phishing actions within the victim’s browser.
Affected Systems
Only the FunnelKit WordPress plugin is affected, specifically versions earlier than 3.15.0.6 and only when the Divi page builder is active. No other vendors or products are listed in the CVE data.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity, while the EPSS score of <1% shows a very low likelihood of exploitation at the present time and it is not listed in the CISA KEV catalog. The attacker simply needs to craft a malicious page that contains the reflected parameter and lure a logged‑in user to visit it. No privileged access or server‑side interaction is required, and the flaw exists only when the Divi builder registers the vulnerable AJAX action.
OpenCVE Enrichment