Return to Global Matrix
CLASSIFIED: EYES ONLY

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

TELEMETRY SUMMARY DECRYPTION

SITREP: A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript into WooCommerce checkout pages, facilitating payment data theft. This exploitation has been reported by Sansec, although the vulnerability lacks an official CVE identifier. TACTICAL ASSESSMENT: The exploitation of this vulnerability poses significant risks to e-commerce security, potentially leading to widespread financial fraud and loss of consumer trust. The absence of a CVE identifier may hinder timely remediation efforts by affected parties. PROJECTED VECTORS: If not addressed promptly, this vulnerability could lead to an increase in cybercriminal activities targeting e-commerce platforms.

SAT-COM 4LAT: 45.192LON: 34.021UTC: 2026-05-16

Event Telemetry

STATUS IDENTIFIERNORMAL TRAFFIC
ORIGIN DESKCYBER
ACQUISITION TIME05/1616:37 ZULU
AUTHORSYSTEM.AUTO[992]