FunnelKit – Funnel Builder for WooCommerce Checkout

Vulnerabilities 13Slug funnel-builderLatest version 3.15.0.2WordPress.org →

Minimum safe version

3.15.0.2

Update to 3.15.0.2 or later to address 13 fixable vulnerabilities

Latest available3.15.0.2
N/A
2026-04-27< 3.15.0.2

FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.1 - Unauthenticated SQL Injection

Medium 6.5
2025-12-06< 3.13.1.3

Funnel Builder by FunnelKit <= 3.13.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Medium 6.4
2025-11-19< 3.13.1.3

CVE-2025-12878

Medium 6.3
2025-11-05< 3.12.0.1

CVE-2025-10567

High 8.8
2025-08-19< 3.11.1

Multiple Plugins By FunnelKit <= (Various Versions) - Authenticated (Contributor+) Sensitive Information Exposure to Privilege Escalation via Woofunnel Library

Medium 6.1
2025-05-15< 3.10.2

Funnel Builder for WordPress by FunnelKit <= 3.10.1 - Authenticated (Administrator+) SQL Injection

Medium 5.4
2024-07-01< 3.4.0

WordPress Funnel Builder for WordPress by FunnelKit Plugin <= 3.3.1 is vulnerable to Cross Site Scripting (XSS)

High 7.6
2024-12-21< 2.14.4

WordPress Funnel Builder for WordPress by FunnelKit Plugin <= 2.14.3 is vulnerable to SQL Injection