Impact
An unauthenticated Cross Site Scripting vulnerability exists in WordPress Funnel Kit Funnel Builder PRO versions 3.15.0.7 and earlier. The flaw, a type of CWE‑79, allows an attacker to inject arbitrary HTML and JavaScript into pages rendered by the plugin, leading to possible execution of malicious scripts in the context of site visitors.
Affected Systems
The affected product is Funnel Kit Funnel Builder PRO by Wisetr INC., with all releases up to and including version 3.15.0.7 impacted. Versions 3.15.0.8 and newer are not affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% means exploitation likelihood is considered low, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires only an arbitrary link or payload that a visitor may click or load; authentication is not required, so any published content using the plugin could serve as an entry point. Once the script runs, attackers can hijack user sessions or extract sensitive information.
OpenCVE Enrichment