Vulnerabilities · 121 days ago
A checkout plugin that can be modified without authentication turns the store itself into the skimmer. Deleting a bad JavaScript file is not enough when the malicious code lives in Funnel Builder’s global settings and keeps firing on every checkout page until that config is cleaned up.
The flaw affects Funnel Builder versions before 3.15.0.3 and is being actively exploited on a plugin installed on more than 40,000 WordPress sites. The payload hides as a fake GTM/Google Analytics script, uses a WebSocket channel, and steals card numbers, CVVs, billing addresses, and other customer data.
That makes the blast radius broader than a single infected page. Any WooCommerce site still on the vulnerable version can keep leaking payments even after a routine file cleanup, because the persistence sits in plugin settings rather than only in dropped code.
2 sources covering this story
Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
Funnel Builder flaw hits 40,000+ stores; fake GTM skimmers steal checkout payment data before patch 3.15.0.3.
Funnel Builder WordPress plugin bug exploited to steal credit cards
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages.
Part of the PlainSec briefing for 2026-05-17