CVE-2026-47100
7.5FunnelKit · Funnel Builder for WooCommerce Checkout
FunnelKit Funnel Builder for WooCommerce Checkout versions prior to 3.15.0.3 contain a missing authorization flaw in the AJAX controller, allowing unauthenticated attackers to perform unauthorized actions.
Executive summary
A critical missing authorization vulnerability in FunnelKit Funnel Builder for WooCommerce Checkout exposes the application to unauthorized actions by unauthenticated attackers.
Vulnerability
This is a Missing Authorization vulnerability (CWE-862) located within the AJAX controller, which fails to verify user permissions, enabling unauthenticated remote attackers to interact with restricted checkout functions.
Business impact
With a CVSS score of 7.5, this vulnerability represents a significant risk to e-commerce operations. An attacker could potentially manipulate checkout processes, alter funnel logic, or gain unauthorized administrative access to the plugin settings, resulting in financial loss or data integrity compromises.
Remediation
Immediate Action: Update the FunnelKit Funnel Builder for WooCommerce Checkout plugin to version 3.15.0.3 or later immediately.
Proactive Monitoring: Monitor WordPress access logs for anomalous requests to the wfacp-ajax-controller.php endpoint or unusual administrative activity within the WooCommerce dashboard.
Compensating Controls: Utilize a Web Application Firewall (WAF) to block suspicious requests directed at the affected AJAX controller path until the plugin can be updated.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Plugin-based vulnerabilities are frequently targeted in automated attacks. Administrators must update the FunnelKit plugin to version 3.15.0.3 or higher immediately to prevent unauthorized modification of their e-commerce checkout flow.