Checkout Plugin Settings Turn WordPress Stores Into Skimmers
A checkout plugin that can be modified without authentication turns the store itself into the skimmer. Deleting a bad JavaScript file is not enough when the malicious code lives in Funnel Builder’s global settings and keeps firing on every checkout page until that config is cleaned up.
The flaw affects Funnel Builder versions before 3.15.0.3 and is being actively exploited on a plugin installed on more than 40,000 WordPress sites. The payload hides as a fake GTM/Google Analytics script, uses a WebSocket channel, and steals card numbers, CVVs, billing addresses, and other customer data.
That makes the blast radius broader than a single infected page. Any WooCommerce site still on the vulnerable version can keep leaking payments even after a routine file cleanup, because the persistence sits in plugin settings rather than only in dropped code.