CVE-2026-42381Active Exploitation

LOWCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-05-15); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-15: 1Mentions · 2026-05-16: 1Active Exploitation · 2026-05-15: 1Active Exploitation · 2026-05-16: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-16: 105-1505-16
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2026-42381 to inject payment skimmers into WooCommerce checkout pages via the Funnel Builder plugin. The SQL injection flaw enabled script propagation across all checkout flows, establishing C2 channels to exfiltrate payment data. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/funnel-builder-flaw-2026-05-16

    Post summary

    Attackers are actively exploiting a SQL injection in the Funnel Builder plugin to deploy payment skimmers, illustrating real‑world use of CVE‑2026‑42381.

    0000066
    1.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2026-42381 to inject payment skimmers into WooCommerce checkout pages via unprotected Funnel Builder endpoints. The attack established WebSocket C2 channels for real-time credit card theft. Runtime egress controls could help detect such exfiltration patterns. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards-2026

    Post summary

    Attackers exploited CVE‑2026‑42381 to inject skimming code into WooCommerce through unsecured Funnel Builder endpoints, using WebSocket C2 channels for real‑time credit card theft.

    0000044
    1.9K followersView on X

Explore more