WordPress Funnel Builder Bug Exposes 40K Sites to Card Theft

Critical flaw in Funnel Builder plugin lets attackers inject malicious scripts, affecting thousands of WooCommerce sites.

By Byte-Pulse Newsroom·AI-augmented editorial system·May 16, 2026·8 min read
Serhat Er — Founder & Editor-in-ChiefEdited bySerhat Er·Founder & Editor-in-Chief
Updated Sep 16, 2026
WordPress Funnel Builder Bug Exposes 40K Sites to Card Theft
Image source: BleepingComputer · Used under fair use for news reporting and commentary.

The recent disclosure of a critical vulnerability in Funnel Builder, a widely deployed WordPress plugin, has sent a ripple of concern through the European e-commerce sector. With over 40,000 websites exposed to potential credit card theft, this incident is far more than a routine security patch; it underscores fundamental challenges in how online businesses, particularly those leveraging the WordPress ecosystem, manage their digital storefronts and protect sensitive customer data. Malicious actors have actively exploited this flaw, injecting harmful JavaScript directly into WooCommerce checkout pages, a move that speaks to a sophisticated understanding of e-commerce payment flows and a clear intent to monetize stolen financial details.

The Anatomy of a Checkout Page Exploit

Security firm Sansec, known for its deep dives into e-commerce platform vulnerabilities, brought this alarming issue to light. Their analysis revealed that the exploit hinges on an unsecured, publicly accessible endpoint within the Funnel Builder plugin. This isn't merely a theoretical weakness; it’s a gaping hole that permits attackers to modify the plugin’s global settings without requiring authentication or specific administrative privileges. The critical vector here is the 'External Scripts' setting, designed innocently enough for site owners to integrate third-party analytics or marketing tags. However, in the hands of an attacker, this becomes a conduit for injecting arbitrary JavaScript, which then executes on every page where the plugin is active, crucially including the WooCommerce checkout process.

Ad

Once injected, the malicious code is designed to blend in, often masquerading as legitimate Google Tag Manager or Google Analytics scripts. This obfuscation is a classic tactic, designed to bypass rudimentary security scans and lull vigilant administrators into a false sense of security. The true danger unfolds when this script establishes a WebSocket connection to a rogue server. This server, controlled by the attackers, then distributes a highly customized payment card skimmer. This isn't a blunt instrument; these skimmers are meticulously crafted to intercept and exfiltrate critical data fields – credit card numbers, CVVs, billing addresses, and other customer information – directly from the checkout form as a customer enters them, often before the data is even submitted to the payment gateway. The sheer sophistication of this chain of attack, from endpoint compromise to data exfiltration, demonstrates a persistent and evolving threat landscape that even well-intentioned plugin developers struggle to keep pace with.

FunnelKit's Swift, Yet Reactive, Response

FunnelKit, the developer behind the Funnel Builder plugin, acted with commendable speed once the vulnerability was identified. They promptly released an updated version, 3.15.0.3, specifically engineered to address this security gap. The company has publicly confirmed the malicious activity and has urged its user base to update their plugins immediately via the standard WordPress dashboard. Beyond the immediate patch, FunnelKit also advised administrators to scrutinize their plugin settings for any unauthorized scripts that might have been surreptitiously added by attackers. While this rapid response is certainly better than a delayed one, it highlights a fundamental challenge: most security measures in the WordPress ecosystem remain inherently reactive. A patch arrives only after an exploit has been discovered and, in this instance, actively weaponized against live e-commerce operations. For businesses, this means operating in a constant state of vigilance, hoping that their chosen vendors are both quick to discover and quick to remedy, a hope that, frankly, is often tested.

The Broader E-Commerce Landscape: A European Perspective

From my perspective, having observed the European tech beat for over a decade, the European e-commerce market finds itself in a particularly precarious position regarding such threats. Its substantial reliance on platforms like WordPress, often augmented by a sprawling array of third-party plugins such as Funnel Builder to enhance conversion rates and streamline customer journeys, creates a complex attack surface. This is not to say other platforms are immune, but the sheer ubiquity and modularity of WordPress, while offering unparalleled flexibility and cost-effectiveness for small to medium-sized enterprises, also introduces a significant security overhead. Each plugin represents a potential new vulnerability, a new door for attackers to exploit. The incident, unfortunately, echoes a long history of vulnerabilities in e-commerce platforms that have led to significant financial losses and, perhaps more damagingly, an erosion of customer trust. With the General Data Protection Regulation (GDPR) firmly in place, European businesses face an additional layer of pressure, carrying the burden of stringent data protection standards and the very real threat of substantial fines for non-compliance following a data breach. The legal and financial ramifications for a European merchant discovered to have lost customer payment data due to a preventable plugin flaw can be catastrophic, far exceeding the immediate costs of the breach itself.

Beyond Funnel Builder: A Pattern of Plugin Vulnerabilities

This Funnel Builder incident is not an isolated event; it fits into a well-established pattern of vulnerabilities in widely-used WordPress plugins. We've seen similar, though perhaps less directly impactful on payment data, issues plague other popular extensions. For instance, in late 2023, a significant arbitrary file upload vulnerability was discovered in the Ultimate Member plugin, affecting over 200,000 sites, allowing unauthenticated users to upload malicious files and potentially take over sites. Earlier, in 2022, the Rank Math SEO plugin, used by over 1.5 million sites, had a high-severity SQL injection flaw that could expose sensitive database information. While these examples didn't directly target payment pages, they illustrate the inherent risks of extending core WordPress functionality with third-party code. In a more direct comparison to payment-related risks, we've observed numerous Cross-Site Scripting (XSS) vulnerabilities in various WooCommerce extensions over the years, which, while not as direct as a payment skimmer, could still be leveraged to redirect users to malicious sites or compromise sessions. The common thread is the complexity introduced by these extensions: each adds new code, new endpoints, and new potential flaws that require constant vigilance, often beyond the capabilities of the average e-commerce site administrator. I'm skeptical that many smaller European businesses truly grasp the cumulative security debt they accrue with every additional plugin they install.

What This Means for European E-Commerce Operators

If you are an administrator or owner of a website utilizing the Funnel Builder plugin, the immediate imperative is clear: update to version 3.15.0.3 or later without delay. This isn't merely a recommendation; it's a critical security mandate. But the task doesn't end with a simple update. You must meticulously review your site's wp_options table or the plugin's 'External Scripts' settings for any suspicious or unauthorized JavaScript that may have been injected. Look for unfamiliar script tags, especially those loading from external, non-Google domains, or scripts encoded in ways that make them difficult to read. Furthermore, consider a full security audit of your site, perhaps with a reputable third-party firm specializing in WordPress security, to ensure no other backdoors or persistent threats remain. For those operating within the EU, this incident carries additional weight. Beyond the direct financial and reputational damage of a breach, you are now squarely in the crosshairs of GDPR compliance. This means not only reporting the breach to supervisory authorities within 72 hours of becoming aware but also potentially notifying affected customers, a process that is both costly and reputationally damaging. The investment in robust security, including regular penetration testing and ongoing monitoring, is no longer an optional expenditure but a fundamental cost of doing business online, especially when handling sensitive customer data.

Lingering Questions and Unaddressed Risks

While FunnelKit has commendably patched the vulnerability, several critical questions remain unanswered, leaving a considerable amount of uncertainty for affected businesses and their customers. Firstly, the full extent of the data breach is still unclear: precisely how many individual credit card numbers and associated customer details were successfully exfiltrated? Without this concrete number, affected businesses struggle to assess the true scope of their liability and the required notification efforts under GDPR. Secondly, while the patch is available, it is uncertain how many of the 40,000+ initially vulnerable websites have actually implemented the necessary updates. Many smaller businesses lack dedicated IT staff or outsource their website maintenance to agencies that may not prioritize immediate security patches, leaving a substantial number of sites still exposed. Thirdly, for how long was this vulnerability actively exploited before Sansec's discovery and FunnelKit's subsequent patch? Understanding the attack window is crucial for forensic analysis and assessing the potential impact. Finally, what specific guidance or tools is FunnelKit providing to help site owners identify and remove the malicious scripts after the patch, beyond a generic recommendation to 'scrutinize settings'? A more automated detection or cleanup tool would significantly alleviate the burden on administrators.

My Take: A Systemic Challenge Demanding Proactive Vigilance

Frankly, this incident is not just a bug in a single plugin; it's a stark reminder of the inherent fragility of the highly modular, open-source e-commerce ecosystem many European businesses rely upon. I believe this situation highlights a systemic problem where the convenience and extensibility of plugins often come at the expense of a truly hardened security posture. The implicit trust placed in third-party developers, many of whom may lack the extensive security audit capabilities of larger software houses, is, in my opinion, a dangerous gamble when handling sensitive financial data. Anyone who has shipped real hardware or managed complex IT infrastructure knows that security cannot be an afterthought, bolted on reactively. It must be designed in from the ground up, with a rigorous, continuous auditing process. For European e-commerce, this means a significant shift in mindset from simply adding features to prioritizing a secure, resilient infrastructure. The cost of a breach, both in terms of fines under GDPR and the irreparable damage to customer trust, far outweighs the perceived savings of a loosely managed, plugin-heavy setup. We need to move beyond reactive patching and foster an environment of proactive security audits, especially for any component that touches payment data. Anything less is, quite simply, an unacceptable risk in the current digital economy.

Sponsored · Affiliate link
Lock down your accounts

Hardware keys and password managers used by security pros.

Shop security gear →
Ad

Discuss this story

Got a take, a correction, or a follow-up tip? Reply where you read — we read everything.

Found an error? File a correction at /corrections. Substantive corrections are logged publicly.

#wordpress#security#woocommerce#credit card#plugin
Get the 5 tech stories worth your time — 3× a week

One short email. The most important Security news, fact-checked, no fluff. Free, unsubscribe anytime.

More from Security

About the author
AI-augmented editorial system

The Byte-Pulse Newsroom is the editorial system that produces Byte-Pulse's daily tech news coverage. Each story is cross-referenced across 3+ independent outlets, drafted with AI assistance by the newsroom system (Drafter → Editor → Fact-Checker → Polisher), and reviewed by Serhat Er, Editor-in-Chief, before publication. We disclose AI augmentation openly. Editorial accountability stays with the named editor on every article. Tips: editorial@byte-pulse.net.

HardwareAIGamingMobileSecurity
Editorially reviewed on . Spotted an error? Tell us.
From other sections

Don’t miss these

Xiaomi 16 Pro vs iPhone 18 Pro: Which Flagship Fits Your World?
📱 Mobile

Xiaomi 16 Pro vs iPhone 18 Pro: Which Flagship Fits Your World?

Deciding between the Xiaomi 16 Pro and iPhone 18 Pro? We break down every spec and trade-off, so you can make the choice that's right for you.

By Serhat Er·14h ago·13 min
Proton VPN vs NordVPN: Which One Earns Your Subscription?
💾 Software

Proton VPN vs NordVPN: Which One Earns Your Subscription?

A deep dive into Proton VPN and NordVPN, comparing their privacy, performance, features, and value, helping you make an informed decision.

By Serhat Er·Sep 20, 2026·9 min
Perplexity Pro vs ChatGPT Plus: Which AI Assistant Fits Your Workflow?
🤖 AI

Perplexity Pro vs ChatGPT Plus: Which AI Assistant Fits Your Workflow?

This guide lays out the strengths and approaches of Perplexity Pro and ChatGPT Plus, helping you identify which AI assistant aligns with your specific needs.

By Serhat Er·Sep 06, 2026·8 min
Pokémon TCG Movie Signals Strategic Media Pivot for The Pokémon Company
🎮 Gaming

Pokémon TCG Movie Signals Strategic Media Pivot for The Pokémon Company

A new Pokémon movie focused on the TCG is coming in 2027, marking a strategic pivot for the franchise as it navigates massive global fan engagement and logistical challenges.

By Byte-Pulse Newsroom·Aug 31, 2026·7 min
Apple's AI Pivot: Vision Pro Content Cut, Siri Rebuilt Amid Layoffs
⚙️ Hardware

Apple's AI Pivot: Vision Pro Content Cut, Siri Rebuilt Amid Layoffs

Apple's latest layoffs signal a strategic pivot, dialing back high-cost Vision Pro content while re-tooling Siri for the AI era. What's next for Apple?

By Byte-Pulse Newsroom·Aug 22, 2026·8 min
Motorola Edge 60 Ultra vs OnePlus 13: Which Android Flagship Fits Your Priorities?
📱 Mobile

Motorola Edge 60 Ultra vs OnePlus 13: Which Android Flagship Fits Your Priorities?

Motorola Edge 60 Ultra and OnePlus 13 both aim for top-tier Android. We cut through the marketing to reveal the true differences, helping you choose.

By Serhat Er·3 days ago·12 min
Ad
Cookies & ads

We fund this site through ads (Google AdSense and others) and use analytics to see what works. Both may set cookies. You decide what is OK — your choice is remembered.

Details in our Privacy Policy.