FunnelKit
cpe:2.3:a:funnelkit:funnel_builder:*:*:*:*:wordpress:*:*
- < 3.15.0.6
A reflected cross-site scripting vulnerability has been identified in the FunnelKit WordPress plugin, affecting versions prior to 3.15.0.6. The issue arises because the plugin fails to properly escape user-supplied parameters before including them in the HTML response of a page-builder AJAX action. This flaw allows unauthenticated attackers to execute scripts that are reflected back to logged-in users who visit a manipulated page. The vulnerability is only present when the Divi builder is active.
Exploitation of this vulnerability allows for reflected cross-site scripting, where an injected script is executed in the context of the user's browser session.
To reproduce this vulnerability, first activate the Divi theme or builder, as the affected AJAX action is only available under Divi. Then, ensure that FunnelKit Funnel Builder version 3.15.0.5 or earlier is active. The vulnerability can be exploited by sending a POST request to 'wp-admin/admin-ajax.php' with the 'action' parameter set to 'et_wfop_optin_form', the 'et_load_builder_modules' parameter set to '1', and the 'input_size' parameter containing the crafted script payload. The absence of a nonce and capability check in the AJAX action response facilitates the exploitation. When a logged-in user opens the crafted page, the injected script executes in their browser.
Users are advised to update the FunnelKit WordPress plugin to version 3.15.0.6 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.