<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:funnelkit:funnel_builder_for_woocommerce_checkout:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afunnelkitfunnel_builder_for_woocommerce_checkout/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 09:51:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afunnelkitfunnel_builder_for_woocommerce_checkout/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in FunnelKit for WooCommerce</title><link>https://feed.craftedsignal.io/briefs/2026-10-funnelkit-xss/</link><pubDate>Sat, 10 Oct 2026 09:51:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-funnelkit-xss/</guid><description>The FunnelKit Funnel Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the shipping_first_name parameter due to insufficient input sanitization.</description><content:encoded><![CDATA[<p>FunnelKit - Funnel Builder for WooCommerce Checkout, a widely used WordPress plugin, contains a critical Stored Cross-Site Scripting (XSS) vulnerability identified as CVE-2026-100147. This vulnerability exists in all versions up to and including 3.16.0.5. The issue stems from inadequate input sanitization and output escaping on the 'shipping_first_name' parameter. An unauthenticated attacker can supply a malicious payload within this field, which is subsequently stored by the application. When a privileged user, such as an administrator, views the checkout or order details page containing the stored payload, the script executes within their browser session. This can lead to unauthorized actions, session hijacking, or the defacement of the affected WordPress site.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. In an administrative context, this could result in full site compromise, unauthorized administrative actions, or the redirection of site traffic. Given the plugin's role in WooCommerce checkout processes, this vulnerability poses a risk to both site integrity and customer data.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the update of the FunnelKit - Funnel Builder for WooCommerce Checkout plugin to a version beyond 3.16.0.5. Detection engineers should inspect web server access logs for anomalous POST requests containing HTML or script tags within checkout-related parameters.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>