The active exploitation of the Funnel Builder plugin is a serious warning for WooCommerce store owners because this flaw directly impacts checkout security and customer payment data. The vulnerability affects Funnel Builder versions before 3.15.0.3 and allows unauthenticated attackers to inject arbitrary JavaScript into checkout pages through the plugin’s external scripts setting. This can be used to deploy payment skimmers that steal credit card numbers, CVVs, billing addresses, and other personal information entered during checkout.

Website owners should immediately update the plugin to version 3.15.0.3 or later and review Settings > Checkout > External Scripts for unfamiliar or suspicious code. Attackers are reportedly disguising malicious scripts as fake Google Tag Manager or analytics code, which makes manual review more difficult. E-commerce security cannot be limited to server patching alone; checkout-page integrity, plugin permissions, script monitoring, and regular code review are now essential.


A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript code into WooCommerce checkout pages with the goal of stealing payment data. Details of the activity were published by Sansec this week. The vulnerability currently does not have an official CVE identifier. It

Source: Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming via The Hacker News — published 16 May 2026.