The active exploitation of the Funnel Builder WordPress plugin is a serious warning for WooCommerce site owners because this is not just a website defacement risk, it directly targets payment data. The flaw affects plugin versions before 3.15.0.3 and can be abused without authentication to inject malicious JavaScript into checkout pages through the plugin’s external scripts setting. Once injected, the skimmer can steal credit card numbers, CVVs, billing addresses, and other customer information during checkout.
E-commerce websites should immediately update Funnel Builder to version 3.15.0.3 or later, review Settings > Checkout > External Scripts for unauthorized code, check server and WordPress logs, and scan checkout pages for suspicious third-party scripts such as fake analytics or tag-manager payloads. Online stores cannot treat plugin updates as routine housekeeping; one vulnerable checkout plugin can become a payment-card theft machine. Because apparently even “conversion optimization” tools now need to be checked for whether they are optimizing conversions for criminals.
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. [...]
Source: Funnel Builder WordPress plugin bug exploited to steal credit cards via Bleeping Computer — published 15 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.