CVE-2026-47100 Details
Description
Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.
A missing authorization vulnerability has been identified in Funnel Builder for WooCommerce Checkout, affecting versions prior to 3.15.0.3. This vulnerability exists in the public checkout endpoint, where it allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Exploitation of this vulnerability enables attackers to inject malicious JavaScript that executes in the browsers of all visitors on the checkout page.
FunnelKit has released a patch for this vulnerability in version 3.15.0.3. Users are advised to update to this version and review the External Scripts setting to remove any unfamiliar scripts. Additionally, running the eComscan tool can help detect any injected skimmers or malware that may have been introduced through this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2026CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Funnel Builder | < 3.15.0.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | [email protected] |
Volerion