Another Major WordPress Plugin Exploited: Hackers Target Credit Card Details, Here’s What You Need to Know


  • Hackers exploit a critical flaw in the Funnel Builder plugin to inject credit card skimmers into payment pages.
  • FunnelKit released a patched version, but more than half of active sites remain on older, vulnerable versions
  • Stolen payment data is monetized through dark web sales and fraudulent ad buys

Hackers are exploiting a critical vulnerability in a popular WordPress plugin to steal the credit card information of people making online purchases.

Security researchers Sansec said they recently spotted an active campaign targeting websites running the Funnel Builder plugin, which is apparently active on more than 40,000 e-commerce sites, allowing businesses to create sales funnels, landing pages, optimized checkout flows, upsells and lead generation campaigns, all without any coding.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top