Skip to content
Threat Feed
high advisory

Stored Cross-Site Scripting in FunnelKit for WooCommerce

The FunnelKit Funnel Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the shipping_first_name parameter due to insufficient input sanitization.

CVE search metadata

CVE search record: CVE-2026-100147. Severity: high. CVSS: 7.2. KEV: no. Product: FunnelKit – Funnel Builder for WooCommerce Checkout (<= 3.16.0.5). Brief: Stored Cross-Site Scripting in FunnelKit for WooCommerce. Brief link: https://feed.craftedsignal.io/briefs/2026-10-funnelkit-xss/

FunnelKit - Funnel Builder for WooCommerce Checkout, a widely used WordPress plugin, contains a critical Stored Cross-Site Scripting (XSS) vulnerability identified as CVE-2026-100147. This vulnerability exists in all versions up to and including 3.16.0.5. The issue stems from inadequate input sanitization and output escaping on the 'shipping_first_name' parameter. An unauthenticated attacker can supply a malicious payload within this field, which is subsequently stored by the application. When a privileged user, such as an administrator, views the checkout or order details page containing the stored payload, the script executes within their browser session. This can lead to unauthorized actions, session hijacking, or the defacement of the affected WordPress site.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. In an administrative context, this could result in full site compromise, unauthorized administrative actions, or the redirection of site traffic. Given the plugin's role in WooCommerce checkout processes, this vulnerability poses a risk to both site integrity and customer data.

Recommendation

Prioritize the update of the FunnelKit - Funnel Builder for WooCommerce Checkout plugin to a version beyond 3.16.0.5. Detection engineers should inspect web server access logs for anomalous POST requests containing HTML or script tags within checkout-related parameters.


Immediate actions

Upgrade FunnelKit - Funnel Builder for WooCommerce Checkout to version > 3.16.0.5

IT Operations 48h

Mitigations

Upgrade to fixed version 3.16.0.6 or later

immediate IT Operations

CVE-2026-100147

Detection coverage 1

Detect CVE-2026-100147 - Stored XSS Attempt in FunnelKit

high

Detects potential Stored XSS exploitation by identifying common script injection patterns within POST requests targeting WooCommerce checkout parameters.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →