Funnel Builder Plugin WooCommerce Checkout Skimming | MSSP Advisory
Critical
DateMay 16, 2026
📋Executive Summary
The Funnel Builder plugin for WordPress contains a critical security vulnerability being actively exploited to inject malicious JavaScript into WooCommerce checkout pages and steal payment data. Attackers are targeting sites running this plugin to deploy checkout skimmers that harvest customer credit card information during the payment process.
⚠️Why It Matters for MSSPs
Your WordPress management tools and client sites running WooCommerce with Funnel Builder are direct targets for credit card theft operations. When payment data gets stolen from client ecommerce sites, you face immediate liability questions about your monitoring and patch management while clients lose revenue and trust during breach response.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.