Unauthenticated Cross Site Scripting Vulnerability in Funnel Builder by FunnelKit
CVE-2026-48966

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-48966?

A vulnerability exists in Funnel Builder by FunnelKit that allows unauthenticated users to execute malicious scripts on affected installations. If a user visits a specially crafted page, potentially harmful scripts may run in the context of their browser, leading to data theft or unauthorized actions within the site. Version 3.15.0.2 and all earlier versions are impacted, necessitating immediate attention to mitigate risks.

Affected Version(s)

Funnel Builder by FunnelKit <= 3.15.0.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tiago Ventura (@perses) | Patchstack Bug Bounty Program
.