Funnel Builder Plugin Flaw Exploited to Skim WooCommerce Stores
A critical unauthenticated vulnerability in the Funnel Builder plugin for WordPress is being exploited to inject payment skimmers into over 40,000 WooCommerce stores. Attackers use a flawed checkout endpoint to plant malicious scripts that steal credit card data and billing information.
**If you use the Funnel Builder (FunnelKit) plugin for WooCommerce, update it immediately to version 3.15.0.3 or later, then check your "External Scripts" settings for any suspicious code (especially fake Google Tag Manager or Analytics scripts) and remove anything you didn't put there yourself. Consider reviewing recent checkout transactions for signs of payment data theft and notify your customers. If you can't update right away, deactivate the plugin until you can.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/funnel-builder-plugin-flaw-exploited-to-skim-40000-woocommerce-stores-8-g-n-l-r/gD2P6Ple2L