GHSA-j8mc-rrx2-537qHighCVSS 7.1

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before...

Published
July 16, 2026
Last Modified
July 16, 2026

🔗 CVE IDs covered (1)

📋 Description

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active.

🔗 References (3)