Another Top WordPress Plugin Exploited – Hackers Target Credit Card Information, Here’s What You Need To Know


  • Hackers are exploiting a critical flaw in the Funnel Builder plugin to inject credit card skimmers into payment pages
  • FunnelKit released a patched version, but more than half of active sites remain on older, vulnerable builds
  • Stolen payment data is monetized through sales on the dark web and fraudulent ad purchases

Hackers are exploiting a critical vulnerability in a popular WordPress plugin to steal credit card information from people making online purchases.

Security researchers Sansec said they recently saw an active campaign targeting sites running the Funnel Builder plugin, which is apparently active on more than 40,000 e-commerce sites that lets businesses create sales funnels, landing pages, optimized payment flows, upsells and lead generation campaigns, all without any coding.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top