Skip to main content

Vendor/product archive

funnelkit / funnel_builder CVEs

Beta · best-effort

5 CVEs tagged to funnelkit / funnel_builder0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2025-2203

Published May 15, 2025

The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-1056

Published Aug 29, 2024

The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_iframe_tag_in_post' function which uses the 'wp_kses_allowed_html…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6836

Published Jul 24, 2024

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is vulnerable to u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5192

Published Jun 29, 2024

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is vulnerable to S…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50856

Published Dec 28, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder for WordPress by FunnelKit – Customize WooCommerce C…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1