CRITICAL ⚡ MUST-KNOW
Funnel Builder WordPress Plugin Flaw Actively Exploited for WooCommerce Payment Skimming
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript into WooCommerce checkout pages, enabling payment card skimming. The flaw has no official CVE identifier as of this writing. Sansec published details of the exploitation activity this week.
WooCommerce store operators using the Funnel Builder plugin should audit checkout pages immediately for unauthorized JavaScript and apply any available plugin updates. Payment card data entered at checkout may be exfiltrated to attacker-controlled infrastructure. Deactivating the plugin until a confirmed patch is available is a prudent interim measure.