FunnelKit records
16 published records for vendor funnelkit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2025-1562Proof of concept | Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrafunnelkit · funnelkit automations · CWE-862 | Critical9.8 | — | 3.3% | Jun 18, 2025 |
35Monitor | CVE-2024-9186Proof of concept | Automation By Autonami < 3.3.0 - Unauthenticated SQLifunnelkit · funnelkit automations · CWE-89 | High8.6 | — | 2.3% | Nov 14, 2024 |
30Monitor | CVE-2023-51672No exploit | WordPress FunnelKit Checkout plugin <= 3.10.3 - Unauthenticated Arbitrary Post/Page Deletion vulnerabilityfunnelkit · funnelkit checkout · CWE-862 | High7.5 | — | 0.5% | Apr 10, 2024 |
28Monitor | CVE-2023-50856No exploit | WordPress Funnel Builder for WordPress by FunnelKit Plugin <= 2.14.3 is vulnerable to SQL Injectionfunnelkit · funnel builder · CWE-89 | High7.2 | — | 0.5% | Dec 28, 2023 |
28Monitor | CVE-2023-50857No exploit | WordPress Automation By Autonami Plugin <= 2.6.1 is vulnerable to SQL Injectionfunnelkit · funnelkit automations · CWE-89 | High7.2 | — | 0.5% | Dec 28, 2023 |
28Monitor | CVE-2024-47328No exploit | WordPress Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin <= 3.1.2 - SQL Injection vulnerabilityfunnelkit · funnelkit automations · CWE-89 | High7.2 | — | 0.5% | Oct 21, 2024 |
24Monitor | CVE-2025-2203No exploit | WooCommerce Checkout & Funnel Builder by FunnelKit < 3.10.2 - Admin+ SQL Injectionfunnelkit · funnel builder · CWE-89 | Medium6.1 | — | 0.3% | May 15, 2025 |
21Monitor | CVE-2025-12468No exploit | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposurefunnelkit · funnelkit automations · CWE-200 | Medium5.3 | — | 0.3% | Nov 5, 2025 |
21Monitor | CVE-2023-51671No exploit | WordPress FunnelKit Checkout plugin <= 3.10.3 - Authenticated Plugin Settings Change vulnerabilityfunnelkit · funnelkit checkout · CWE-862 | Medium5.4 | — | 0.3% | Jun 12, 2024 |
21Monitor | CVE-2024-5192No exploit | Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticatedfunnelkit · funnel builder · CWE-79 | Medium5.4 | — | 0.3% | Jun 29, 2024 |
21Monitor | CVE-2024-1056No exploit | Funnel Kit Funnel Builder PRO <= 3.4.5 Authenticated(Contributor+) Stored Cross-Site Scripting via allow_iframe_tag_in_postfunnelkit · funnel builder · CWE-79 | Medium5.4 | — | 0.3% | Aug 29, 2024 |
21Monitor | CVE-2024-13675No exploit | SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scriptingfunnelkit · slingblocks · CWE-79 | Medium5.4 | — | 0.2% | Mar 8, 2025 |
17Monitor | CVE-2022-2389No exploit | Automations By Autonami < 2.1.2 - Subscriber+ Automation Creationfunnelkit · funnelkit automations · CWE-352 | Medium4.3 | — | 0.4% | Aug 22, 2022 |
17Monitor | CVE-2024-6836No exploit | Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Authofunnelkit · funnel builder · CWE-862 | Medium4.3 | — | 0.3% | Jul 24, 2024 |
17Monitor | CVE-2023-51670No exploit | WordPress FunnelKit Checkout plugin <= 3.10.3 - Authenticated Arbitrary Plugin Activation vulnerabilityfunnelkit · funnelkit checkout · CWE-862 | Medium4.3 | — | 0.3% | Jun 12, 2024 |
17Monitor | CVE-2025-12469No exploit | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrafunnelkit · funnelkit automations · CWE-862 | Medium4.3 | — | 0.2% | Nov 5, 2025 |
- CVE-2025-156240Plan
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitra
CriticalCVSS 9.8Proof of conceptEPSS 3%funnelkit · funnelkit automationsJun 18, 2025
- CVE-2024-918635Monitor
Automation By Autonami < 3.3.0 - Unauthenticated SQLi
HighCVSS 8.6Proof of conceptEPSS 2%funnelkit · funnelkit automationsNov 14, 2024
- CVE-2023-5167230Monitor
WordPress FunnelKit Checkout plugin <= 3.10.3 - Unauthenticated Arbitrary Post/Page Deletion vulnerability
HighCVSS 7.5No exploitEPSS 1%funnelkit · funnelkit checkoutApr 10, 2024
- CVE-2023-5085628Monitor
WordPress Funnel Builder for WordPress by FunnelKit Plugin <= 2.14.3 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%funnelkit · funnel builderDec 28, 2023
- CVE-2023-5085728Monitor
WordPress Automation By Autonami Plugin <= 2.6.1 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%funnelkit · funnelkit automationsDec 28, 2023
- CVE-2024-4732828Monitor
WordPress Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin <= 3.1.2 - SQL Injection vulnerability
HighCVSS 7.2No exploitEPSS 0%funnelkit · funnelkit automationsOct 21, 2024
- CVE-2025-220324Monitor
WooCommerce Checkout & Funnel Builder by FunnelKit < 3.10.2 - Admin+ SQL Injection
MediumCVSS 6.1No exploitEPSS 0%funnelkit · funnel builderMay 15, 2025
- CVE-2025-1246821Monitor
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure
MediumCVSS 5.3No exploitEPSS 0%funnelkit · funnelkit automationsNov 5, 2025
- CVE-2023-5167121Monitor
WordPress FunnelKit Checkout plugin <= 3.10.3 - Authenticated Plugin Settings Change vulnerability
MediumCVSS 5.4No exploitEPSS 0%funnelkit · funnelkit checkoutJun 12, 2024
- CVE-2024-519221Monitor
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticated
MediumCVSS 5.4No exploitEPSS 0%funnelkit · funnel builderJun 29, 2024
- CVE-2024-105621Monitor
Funnel Kit Funnel Builder PRO <= 3.4.5 Authenticated(Contributor+) Stored Cross-Site Scripting via allow_iframe_tag_in_post
MediumCVSS 5.4No exploitEPSS 0%funnelkit · funnel builderAug 29, 2024
- CVE-2024-1367521Monitor
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%funnelkit · slingblocksMar 8, 2025
- CVE-2022-238917Monitor
Automations By Autonami < 2.1.2 - Subscriber+ Automation Creation
MediumCVSS 4.3No exploitEPSS 0%funnelkit · funnelkit automationsAug 22, 2022
- CVE-2024-683617Monitor
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Autho
MediumCVSS 4.3No exploitEPSS 0%funnelkit · funnel builderJul 24, 2024
- CVE-2023-5167017Monitor
WordPress FunnelKit Checkout plugin <= 3.10.3 - Authenticated Arbitrary Plugin Activation vulnerability
MediumCVSS 4.3No exploitEPSS 0%funnelkit · funnelkit checkoutJun 12, 2024
- CVE-2025-1246917Monitor
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitra
MediumCVSS 4.3No exploitEPSS 0%funnelkit · funnelkit automationsNov 5, 2025