Impact
This vulnerability is a flaw in the Funnel Builder by FunnelKit plugin that fails to neutralize user input before rendering it in the browser, which allows attackers to embed arbitrary JavaScript that will run in the context of a victim’s session. If exploited, the script can steal credentials, hijack sessions, deface the site, or perform other malicious actions that compromise confidentiality, integrity, or availability of the user’s data.
Affected Systems
The defect applies to all WordPress instances that have the Funnel Builder by FunnelKit plugin installed in a version up through 3.15.0.8. Any site using these vulnerable plugin releases is exposed.
Risk and Exploitability
The CVSS score of 7.1 denotes a high‑impact vulnerability that can be triggered via a web‑based attack, such as a malicious link or a crafted form submission that is echoed by the plugin. The EPSS score, being less than 1%, indicates that active exploitation is currently rare, and the feature is not listed in the CISA KEV catalog, further reducing the likelihood of a coordinated attack. Nonetheless, the potential for offline or insider threats remains, and the impact on user browsers warrants timely remediation.
OpenCVE Enrichment