Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

An unpatched critical vulnerability in the FunnelKit Funnel Builder WordPress plugin is being actively exploited to inject card-skimming code into WooCommerce checkout pages across an estimated 40,000+ installations. Attackers write malicious JavaScript directly into plugin settings without authentication, capturing payment card numbers, CVVs, and billing data from customers at the moment of purchase. Sites still running versions before 3.15.0.3 are actively exposing customer payment data; sites already compromised may remain infected even after patching unless skimmer code is explicitly removed.

Author

Tech Jacks Solutions