Breach404
Back to Insights
Secure Software2 min readMay 16, 2026

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

A critical vulnerability in the Funnel Builder plugin for WooCommerce is being actively exploited to inject malicious code into checkout pages, allowing attackers to steal customer payment information and sensitive data. Organizations using WooCommerce wi

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free