A critical vulnerability in Funnel Builder by FunnelKit, a WooCommerce checkout and upsell plugin used by more than 40,000 stores, has been actively exploited to inject malicious JavaScript into checkout pages. The flaw affects all versions before 3.15.0.3 and stems from a public checkout endpoint that allowed unauthenticated attackers to modify the plugin’s global settings, including the External Scripts option, without proper capability checks.
Attackers used the weakness to plant fake Google Tag Manager or analytics-style code that loaded a payment skimmer and stole card numbers, CVVs, billing addresses, and other customer data during checkout. Sansec said one observed attack chain fetched code from analytics-reports[.]com and opened a WebSocket connection to protect-wss[.]com to deliver a store-specific skimmer. FunnelKit released version 3.15.0.3 to restrict the endpoint to safe methods and add authorization checks, and defenders have been urged to update immediately and review the plugin’s External Scripts configuration for unauthorized entries.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
FunnelKit released version 3.15.0.3 to address the flaw by adding capability checks and restricting the vulnerable endpoint to an allow-list of safe methods. The vendor also acknowledged that attackers had been able to inject scripts through the plugin.
Sansec reported that the Funnel Builder vulnerability was being actively exploited and described one observed attack chain in which a loader fetched code from analytics-reports[.]com and opened a WebSocket to protect-wss[.]com to retrieve a store-specific skimmer. The firm said the issue affected all versions before 3.15.0.3 and threatened more than 40,000 WooCommerce stores.
Attackers abused an unauthenticated public checkout endpoint in Funnel Builder by FunnelKit to modify the plugin’s global settings and insert malicious JavaScript into WooCommerce checkout pages. The injected code masqueraded as Google Tag Manager or analytics scripts and stole payment card data, CVVs, billing addresses, and other customer information.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcesansec.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.