{"id":144,"date":"2026-05-15T20:42:51","date_gmt":"2026-05-15T20:42:51","guid":{"rendered":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/"},"modified":"2026-05-15T20:42:51","modified_gmt":"2026-05-15T20:42:51","slug":"funnel-builder-plugin-exploited-to-steal-credit-cards","status":"publish","type":"post","link":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/","title":{"rendered":"Funnel Builder Plugin Exploited To Steal Credit Cards"},"content":{"rendered":"<p>Thousands of WordPress websites running the popular Funnel Builder plugin have become targets in a sophisticated credit card theft campaign that exploits a critical security vulnerability. This attack demonstrates how cybercriminals continue to target e-commerce platforms through third-party plugins, turning legitimate business websites into unwitting accomplices in financial fraud schemes that impact both merchants and their customers.<\/p>\n<h2>What Happened<\/h2>\n<p>Security researchers have identified an active exploitation campaign targeting the Funnel Builder plugin, a widely used WordPress tool that helps businesses create sales funnels and checkout pages. The vulnerability allows attackers to inject malicious code into websites without authentication, effectively compromising the payment processing flow. Once exploited, the compromised websites capture customer credit card information as it is entered during legitimate transactions. This stolen financial data is then transmitted to servers controlled by the attackers, who can sell the information on underground marketplaces or use it for fraudulent purchases. The vulnerability affects multiple versions of the plugin, and evidence suggests that attackers have been actively scanning for vulnerable installations across the internet. Website owners may remain completely unaware that their sites have been compromised, as the malicious code operates silently in the background without disrupting normal business operations or alerting administrators to suspicious activity.<\/p>\n<h2>How It Works<\/h2>\n<p>The attack exploits a vulnerability in the Funnel Builder plugin that fails to properly sanitize and validate user input. Attackers leverage this weakness to inject malicious JavaScript code directly into the checkout pages created by the plugin. This technique, known as cross-site scripting or XSS, allows cybercriminals to insert card skimming scripts that monitor user input fields in real-time. When customers enter their payment information including credit card numbers, expiration dates, and security codes, the malicious code captures this data before it reaches the legitimate payment processor. The stolen information is then encoded and transmitted to attacker-controlled servers, often disguised as legitimate requests to avoid detection by security monitoring tools. The sophistication of these attacks lies in their ability to remain invisible to both website administrators and customers. The checkout process appears to function normally, orders are processed successfully, and customers receive their purchases without any indication that their financial information has been compromised. This makes detection particularly challenging, as there are no obvious signs of malicious activity until fraudulent charges begin appearing on customer accounts, sometimes weeks or months after the initial theft.<\/p>\n<h2>What You Should Do<\/h2>\n<p>Website owners using the Funnel Builder plugin must take immediate action to protect their sites and customers. First, update the plugin to the latest patched version immediately, as the developers have released security fixes addressing this vulnerability. Conduct a thorough security audit of your website to identify any unauthorized code modifications or suspicious files that may have been added. Implement web application firewalls and security monitoring solutions specifically designed for WordPress environments to detect and block exploitation attempts. Review your payment processing setup and consider using tokenization or redirecting customers to secure, PCI-compliant payment gateways that handle sensitive data off-site. For customers who suspect they may have been affected, monitor credit card statements closely for unauthorized transactions, consider placing fraud alerts with credit bureaus, and report any suspicious activity to financial institutions immediately. Organizations should also notify customers of the potential breach in accordance with data protection regulations and offer credit monitoring services where appropriate.<\/p>\n<p>This incident reinforces the critical importance of maintaining updated plugins and implementing comprehensive security measures for e-commerce platforms. As cybercriminals continue developing sophisticated techniques to exploit third-party components, businesses must remain vigilant and proactive in protecting customer data.<\/p>\n<p>Stay protected with CyDhaal. Follow us at cydhaal.com for daily updates.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Funnel Builder plugin flaw actively exploited to inject card-stealing malware into WordPress checkout pages. 400K+ sites at risk. Patch immediately.<\/p>\n","protected":false},"author":1,"featured_media":143,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-144","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersspionage"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Funnel Builder Plugin Exploited To Steal Credit Cards - CyDhaal - Your Daily Dose of Cyber Intelligence<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Funnel Builder Plugin Exploited To Steal Credit Cards - CyDhaal - Your Daily Dose of Cyber Intelligence\" \/>\n<meta property=\"og:description\" content=\"Critical Funnel Builder plugin flaw actively exploited to inject card-stealing malware into WordPress checkout pages. 400K+ sites at risk. Patch immediately.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/\" \/>\n<meta property=\"og:site_name\" content=\"CyDhaal - Your Daily Dose of Cyber Intelligence\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-15T20:42:51+00:00\" \/>\n<meta name=\"author\" content=\"CyDhaal Admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"CyDhaal Admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/\"},\"author\":{\"name\":\"CyDhaal Admin\",\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/#\\\/schema\\\/person\\\/0e04b4db0d31604a28212b8978e334e4\"},\"headline\":\"Funnel Builder Plugin Exploited To Steal Credit Cards\",\"datePublished\":\"2026-05-15T20:42:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/\"},\"wordCount\":607,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.cydhaal.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/cydhaal-47.jpg\",\"articleSection\":[\"Cyber Espionage\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/\",\"url\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/\",\"name\":\"Funnel Builder Plugin Exploited To Steal Credit Cards - CyDhaal - Your Daily Dose of Cyber Intelligence\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.cydhaal.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/cydhaal-47.jpg\",\"datePublished\":\"2026-05-15T20:42:51+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/#\\\/schema\\\/person\\\/0e04b4db0d31604a28212b8978e334e4\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/#primaryimage\",\"url\":\"https:\\\/\\\/blog.cydhaal.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/cydhaal-47.jpg\",\"contentUrl\":\"https:\\\/\\\/blog.cydhaal.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/cydhaal-47.jpg\",\"width\":1024,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/2026\\\/05\\\/15\\\/funnel-builder-plugin-exploited-to-steal-credit-cards\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/blog.cydhaal.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Funnel Builder Plugin Exploited To Steal Credit Cards\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/#website\",\"url\":\"https:\\\/\\\/blog.cydhaal.com\\\/\",\"name\":\"CyDhaal - Your Daily Dose of Cyber Intelligence\",\"description\":\"Daily Cyber Threats. Zero Noise\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/blog.cydhaal.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/blog.cydhaal.com\\\/#\\\/schema\\\/person\\\/0e04b4db0d31604a28212b8978e334e4\",\"name\":\"CyDhaal Admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e91488823450d58fabed37d4a7c92fb74adfe87dec1074ae7eca410c326b8a01?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e91488823450d58fabed37d4a7c92fb74adfe87dec1074ae7eca410c326b8a01?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e91488823450d58fabed37d4a7c92fb74adfe87dec1074ae7eca410c326b8a01?s=96&d=mm&r=g\",\"caption\":\"CyDhaal Admin\"},\"sameAs\":[\"https:\\\/\\\/blog.cydhaal.com\"],\"url\":\"https:\\\/\\\/blog.cydhaal.com\\\/index.php\\\/author\\\/jagsinghcansinghgmail-com\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Funnel Builder Plugin Exploited To Steal Credit Cards - CyDhaal - Your Daily Dose of Cyber Intelligence","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/","og_locale":"en_US","og_type":"article","og_title":"Funnel Builder Plugin Exploited To Steal Credit Cards - CyDhaal - Your Daily Dose of Cyber Intelligence","og_description":"Critical Funnel Builder plugin flaw actively exploited to inject card-stealing malware into WordPress checkout pages. 400K+ sites at risk. Patch immediately.","og_url":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/","og_site_name":"CyDhaal - Your Daily Dose of Cyber Intelligence","article_published_time":"2026-05-15T20:42:51+00:00","author":"CyDhaal Admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"CyDhaal Admin","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/#article","isPartOf":{"@id":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/"},"author":{"name":"CyDhaal Admin","@id":"https:\/\/blog.cydhaal.com\/#\/schema\/person\/0e04b4db0d31604a28212b8978e334e4"},"headline":"Funnel Builder Plugin Exploited To Steal Credit Cards","datePublished":"2026-05-15T20:42:51+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/"},"wordCount":607,"commentCount":0,"image":{"@id":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.cydhaal.com\/wp-content\/uploads\/2026\/05\/cydhaal-47.jpg","articleSection":["Cyber Espionage"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/","url":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/","name":"Funnel Builder Plugin Exploited To Steal Credit Cards - CyDhaal - Your Daily Dose of Cyber Intelligence","isPartOf":{"@id":"https:\/\/blog.cydhaal.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/#primaryimage"},"image":{"@id":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.cydhaal.com\/wp-content\/uploads\/2026\/05\/cydhaal-47.jpg","datePublished":"2026-05-15T20:42:51+00:00","author":{"@id":"https:\/\/blog.cydhaal.com\/#\/schema\/person\/0e04b4db0d31604a28212b8978e334e4"},"breadcrumb":{"@id":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/#primaryimage","url":"https:\/\/blog.cydhaal.com\/wp-content\/uploads\/2026\/05\/cydhaal-47.jpg","contentUrl":"https:\/\/blog.cydhaal.com\/wp-content\/uploads\/2026\/05\/cydhaal-47.jpg","width":1024,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/blog.cydhaal.com\/index.php\/2026\/05\/15\/funnel-builder-plugin-exploited-to-steal-credit-cards\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.cydhaal.com\/"},{"@type":"ListItem","position":2,"name":"Funnel Builder Plugin Exploited To Steal Credit Cards"}]},{"@type":"WebSite","@id":"https:\/\/blog.cydhaal.com\/#website","url":"https:\/\/blog.cydhaal.com\/","name":"CyDhaal - Your Daily Dose of Cyber Intelligence","description":"Daily Cyber Threats. Zero Noise","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.cydhaal.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.cydhaal.com\/#\/schema\/person\/0e04b4db0d31604a28212b8978e334e4","name":"CyDhaal Admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/e91488823450d58fabed37d4a7c92fb74adfe87dec1074ae7eca410c326b8a01?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/e91488823450d58fabed37d4a7c92fb74adfe87dec1074ae7eca410c326b8a01?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e91488823450d58fabed37d4a7c92fb74adfe87dec1074ae7eca410c326b8a01?s=96&d=mm&r=g","caption":"CyDhaal Admin"},"sameAs":["https:\/\/blog.cydhaal.com"],"url":"https:\/\/blog.cydhaal.com\/index.php\/author\/jagsinghcansinghgmail-com\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.cydhaal.com\/index.php\/wp-json\/wp\/v2\/posts\/144","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.cydhaal.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.cydhaal.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.cydhaal.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.cydhaal.com\/index.php\/wp-json\/wp\/v2\/comments?post=144"}],"version-history":[{"count":0,"href":"https:\/\/blog.cydhaal.com\/index.php\/wp-json\/wp\/v2\/posts\/144\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.cydhaal.com\/index.php\/wp-json\/wp\/v2\/media\/143"}],"wp:attachment":[{"href":"https:\/\/blog.cydhaal.com\/index.php\/wp-json\/wp\/v2\/media?parent=144"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.cydhaal.com\/index.php\/wp-json\/wp\/v2\/categories?post=144"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.cydhaal.com\/index.php\/wp-json\/wp\/v2\/tags?post=144"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}