WordPress Funnel Builder Payment Data Theft Vulnerability | MSSP Advisory

High
DateMay 15, 2026
📋Executive Summary
A vulnerability in the WordPress Funnel Builder plugin, installed on over 40,000 websites, allows unauthenticated attackers to modify global settings through an unprotected checkout endpoint. Attackers can manipulate payment processing settings to redirect transaction data to their own systems, stealing payment information during checkout processes. The plugin handles e-commerce funnel creation and payment processing for WordPress sites.
⚠️Why It Matters for MSSPs
WordPress sites running Funnel Builder in your client environments are bleeding payment data to attackers right now, and you cannot patch this fast enough through normal update cycles. Your own marketing or billing WordPress instances could be compromised if running this plugin, exposing client payment information from your invoicing processes.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.