CVE-2026-47100: Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX
Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.
Security readout for executives and security teams
Plain-English summary
Attackers can remotely alter a vulnerable WooCommerce checkout plugin without logging in. They can place malicious JavaScript into a global setting, causing it to run for every checkout visitor. This threatens customer browser sessions and checkout integrity.
Executive priority
Prioritize immediate patching and compromise assessment for public checkout systems. Because reported exploitation can persistently affect every checkout visitor, remediation should include configuration and log review rather than treating an upgrade alone as sufficient.
Technical view
Funnel Builder for WooCommerce Checkout before 3.15.0.3 lacks authorization enforcement on a public AJAX checkout endpoint. An unauthenticated requester can invoke internal methods and write arbitrary data to the global External Scripts setting, creating persistent JavaScript execution on checkout pages. The issue is classified as CWE-862 and scored CVSS 4.0 8.7.
Likely exposure
Internet-accessible WordPress stores using Funnel Builder for WooCommerce Checkout earlier than 3.15.0.3 are exposed. Exploitation requires no authentication or user interaction from the attacker. Impact reaches checkout visitors after malicious script is stored.
Exploitation context
Sansec reports that this vulnerability has been exploited. However, the supplied record states it is not in CISA's KEV catalog. The evidence supports treating exposed stores as potentially compromised, but does not establish the scale or targets of exploitation.
Researcher notes
The published patch changeset is the strongest source for comparing authorization behavior between releases. Defenders should examine historical External Scripts values and endpoint activity. Available evidence confirms unauthorized persistent script injection, but the supplied sources do not quantify exploitation prevalence or document every downstream consequence.
Mitigation direction
Upgrade Funnel Builder for WooCommerce Checkout to version 3.15.0.3 or later.
Review the plugin's External Scripts setting and remove unauthorized content.
Follow current FunnelKit guidance if upgrading cannot be completed immediately.
Begin incident response if unexpected scripts or setting changes are found.
Validation and detection
Inventory the installed plugin version across every WooCommerce site.
Confirm production instances run version 3.15.0.3 or later.
Inspect External Scripts for unfamiliar JavaScript, domains, or recent changes.
Review web and application logs for suspicious public checkout endpoint activity.
Verify rendered checkout pages contain only approved scripts after remediation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-862: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-862 · source CWE mapping
Missing Authorization
Missing Authorization represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.