FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.1 - Unauthenticated SQL Injection
FunnelKit – Funnel Builder for WooCommerce Checkout
Minimum safe version
3.15.0.2
Update to 3.15.0.2 or later to address 13 fixable vulnerabilities
CVE-2025-14169
Funnel Builder by FunnelKit <= 3.13.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-12878
CVE-2025-10567
CVE-2025-54750
Multiple Plugins By FunnelKit <= (Various Versions) - Authenticated (Contributor+) Sensitive Information Exposure to Privilege Escalation via Woofunnel Library
CVE-2025-49034
Funnel Builder for WordPress by FunnelKit <= 3.10.1 - Authenticated (Administrator+) SQL Injection
CVE-2025-26979
CVE-2024-6836
WordPress Funnel Builder for WordPress by FunnelKit Plugin <= 3.3.1 is vulnerable to Cross Site Scripting (XSS)
WordPress Funnel Builder for WordPress by FunnelKit Plugin <= 2.14.3 is vulnerable to SQL Injection