Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.15.0.8.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a flaw in the Funnel Builder by FunnelKit plugin that fails to neutralize user input before rendering it in the browser, which allows attackers to embed arbitrary JavaScript that will run in the context of a victim’s session. If exploited, the script can steal credentials, hijack sessions, deface the site, or perform other malicious actions that compromise confidentiality, integrity, or availability of the user’s data.

Affected Systems

The defect applies to all WordPress instances that have the Funnel Builder by FunnelKit plugin installed in a version up through 3.15.0.8. Any site using these vulnerable plugin releases is exposed.

Risk and Exploitability

The CVSS score of 7.1 denotes a high‑impact vulnerability that can be triggered via a web‑based attack, such as a malicious link or a crafted form submission that is echoed by the plugin. The EPSS score, being less than 1%, indicates that active exploitation is currently rare, and the feature is not listed in the CISA KEV catalog, further reducing the likelihood of a coordinated attack. Nonetheless, the potential for offline or insider threats remains, and the impact on user browsers warrants timely remediation.

Generated by OpenCVE AI on August 1, 2026 at 10:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Funnel Builder by FunnelKit to any version newer than 3.15.0.8
  • If an upgrade cannot be performed immediately, temporarily disable the plugin or restrict its use to trusted administrators
  • Audit any custom templates or code that renders plugin data and ensure proper escaping or sanitization against XSS

Generated by OpenCVE AI on August 1, 2026 at 10:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Funnelkit
Funnelkit funnel Builder By Funnelkit
Wordpress
Wordpress wordpress
Vendors & Products Funnelkit
Funnelkit funnel Builder By Funnelkit
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.15.0.8.
Title WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Funnelkit Funnel Builder By Funnelkit
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:38:09.832Z

Reserved: 2026-06-25T08:05:16.224Z

Link: CVE-2026-57816

cve-icon Vulnrichment

Updated: 2026-07-13T13:54:26.531Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')