Skip to content
Noroxi

FunnelKit records

16 published records for vendor funnelkit.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
50%
Median publish → KEV
No record has entered KEV

All records

16 records
  • Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitra

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    funnelkit · funnelkit automationsJun 18, 2025

  • CVE-2024-9186
    35Monitor

    Automation By Autonami < 3.3.0 - Unauthenticated SQLi

    HighCVSS 8.6Proof of conceptEPSS 2%

    funnelkit · funnelkit automationsNov 14, 2024

  • WordPress FunnelKit Checkout plugin <= 3.10.3 - Unauthenticated Arbitrary Post/Page Deletion vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    funnelkit · funnelkit checkoutApr 10, 2024

  • WordPress Funnel Builder for WordPress by FunnelKit Plugin <= 2.14.3 is vulnerable to SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    funnelkit · funnel builderDec 28, 2023

  • WordPress Automation By Autonami Plugin <= 2.6.1 is vulnerable to SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    funnelkit · funnelkit automationsDec 28, 2023

  • WordPress Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin <= 3.1.2 - SQL Injection vulnerability

    HighCVSS 7.2No exploitEPSS 0%

    funnelkit · funnelkit automationsOct 21, 2024

  • CVE-2025-2203
    24Monitor

    WooCommerce Checkout & Funnel Builder by FunnelKit < 3.10.2 - Admin+ SQL Injection

    MediumCVSS 6.1No exploitEPSS 0%

    funnelkit · funnel builderMay 15, 2025

  • FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure

    MediumCVSS 5.3No exploitEPSS 0%

    funnelkit · funnelkit automationsNov 5, 2025

  • WordPress FunnelKit Checkout plugin <= 3.10.3 - Authenticated Plugin Settings Change vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    funnelkit · funnelkit checkoutJun 12, 2024

  • CVE-2024-5192
    21Monitor

    Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticated

    MediumCVSS 5.4No exploitEPSS 0%

    funnelkit · funnel builderJun 29, 2024

  • CVE-2024-1056
    21Monitor

    Funnel Kit Funnel Builder PRO <= 3.4.5 Authenticated(Contributor+) Stored Cross-Site Scripting via allow_iframe_tag_in_post

    MediumCVSS 5.4No exploitEPSS 0%

    funnelkit · funnel builderAug 29, 2024

  • SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    funnelkit · slingblocksMar 8, 2025

  • CVE-2022-2389
    17Monitor

    Automations By Autonami < 2.1.2 - Subscriber+ Automation Creation

    MediumCVSS 4.3No exploitEPSS 0%

    funnelkit · funnelkit automationsAug 22, 2022

  • CVE-2024-6836
    17Monitor

    Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Autho

    MediumCVSS 4.3No exploitEPSS 0%

    funnelkit · funnel builderJul 24, 2024

  • WordPress FunnelKit Checkout plugin <= 3.10.3 - Authenticated Arbitrary Plugin Activation vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    funnelkit · funnelkit checkoutJun 12, 2024

  • FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitra

    MediumCVSS 4.3No exploitEPSS 0%

    funnelkit · funnelkit automationsNov 5, 2025