Another Top WordPress Plugin Exploited: Hackers Target Credit Card Data, Here’s What You Need to Know



  • Hackers are exploiting a critical flaw in the Funnel Builder plugin to inject credit card skimmers into checkout pages.
  • FunnelKit released a patched version, but more than half of active sites remain on older, more vulnerable versions.
  • Stolen payment data is monetized through dark web sales and fraudulent ad purchases

Hackers are exploiting a critical vulnerability in a popular WordPress plugin to steal credit card information from people making online purchases.

Security researchers Sansec said they recently detected an active campaign targeting websites running the Funnel Builder plugin, which is apparently active on more than 40,000 e-commerce websites, allowing businesses to create sales funnels, landing pages, optimized checkout flows, upsells, and lead generation campaigns, all without any coding.

Leave a Comment

Your email address will not be published. Required fields are marked *