CVE-2026-47100Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-05-19); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-19: 2Mentions · 2026-05-25: 1Mentions · 2026-05-30: 1Mentions · 2026-06-05: 1Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-06-05: 1Technical Details · 2026-05-19: 2Technical Details · 2026-05-25: 1Technical Details · 2026-05-30: 1Technical Details · 2026-06-05: 105-1905-2505-3006-05
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-192
Disclosure2
2026-05-251
Disclosure1
2026-05-301
Patch1
2026-06-051
General1
Full discourse5 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-47100 Funnel Builder for WooCommerce Checkoutの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/03/cve-2026-47100-funnel-builder-for-woocommerce-checkout/ #IT #Security #cybersecurity

    Post summary

    The article gives an overview of CVE-2026-47100 affecting Funnel Builder for WooCommerce Checkout, explaining the vulnerability and outlining impact and countermeasures including patches or mitigations.

    0001039
    209 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-47100 (CVSS 7.5) Funnel Builder for WooCommerce <3[.]15[.]0[.]3 allows unauthenticated attackers to inject malicious JavaScript on checkout pages via missing authorization flaw. Update immediately. #CVE #Vulnerability #PatchNow https://t.co/AqhYyAoM02

    Post summary

    The tweet announces a high‑severity vulnerability (CVE‑2026‑47100) in Funnel Builder for WooCommerce that allows unauthenticated JavaScript injection, and urges users to apply the available patch immediately.

    0000051
    32 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    WooCommerce Funnel の脆弱性 CVE-2026-47100 が FIX:4万サイト超に決済情報窃取のリスク https://iototsecnews.jp/2026/05/18/critical-funnelkit-vulnerability-puts-40000-woocommerce-sites-at-risk/ 今回の WooCommerce の Funnel Builder プラグインで発生した問題の原因は、プラグイン内にある公開エンドポイントのセキュリティ対策が不十分だったことにあります。本来であれば、システムを操作する前にユーザーの権限を正しく検証し、アクセス制限を行う必要がありますが、それが実施されていませんでした。そのため、未認証の攻撃者からのリクエストにより、設定を更新する内部関数が直接呼び出せる状態になっていました。この欠陥を突く攻撃者により、悪意のスクリプトが追加され、大切な決済データが流出するリスクに繋がってしまいました。ご利用のチームは、ご注意ください。 #CVE202647100 #FunnelBuilder #Vulnerability #Woocommerce

    Post summary

    An unauthenticated access flaw in WooCommerce Funnel Builder lets attackers trigger internal configuration changes that could leak payment data, affecting more than 40,000 sites; a fix has been announced, but specific patch details are not provided.

    0000068
    490 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47100 Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated a… https://www.cve.org/CVERecord?id=CVE-2026-47100

    Post summary

    The excerpt announces a missing authorization flaw in Funnel Builder for WooCommerce Checkout prior to version 3.15.0.3, providing technical details but no PoC, exploit, patch, or evidence of active exploitation.

    00000122
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-47100 Unauthenticated Authorization Bypass in Funnel Builder for WooCommerce Checkout Prior to 3.15.0.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-47100

    Post summary

    An unauthenticated authorization bypass flaw exists in Funnel Builder for WooCommerce Checkout versions prior to 3.15.0.3, identified by CVE‑2026‑47100.

    0000055
    4.0K followersView on X

Explore more