Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
FunnelKit -We are Hiring !

FunnelKit -We are Hiring ! Vendor Cyber Rating & Cyber Score

funnelkit.com

Hi There! Thanks for dropping by to get to know us more. We are NOT a passionate team of coders, marketers, or designers - NADA. We are a passionate team of Problem-Solvers! Each member of our team is dedicated to solving problems in the WooCommerce space through innovation and design. We started this company back in 2011, as a web-consultancy, building custom solutions for our international clients. But as we progressed, we began to spot gaps in the market, and instead of sitting back, we decided to rise up and fill in those gaps. Our products are now serving more than 30,000 happy stores, across the globe today. As a team, we believe in an open-door policy and flexible timings. We host brainstorming & growth sessions, each month so


F-H A.I CyberSecurity Scoring

F-H
Company Information
Website:https://funnelkit.com
Employees number:21
Number of followers:4,093
NAICS:5112
Industry Type:Software Development
Homepage:funnelkit.com
F-H Risk Score (AI oriented)
Between 650 and 699
logo
F-HSoftware Development
Updated:
15/05/2026
656/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
F-H Global Score (TPRM)
xxxx
logo
F-HSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

F-H
F-HWeak
Current Score
656B (WEAK)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
660Before Incident
JUNE 2026
659Before Incident
MAY 2026
661Before Incident
Vulnerability
14 May 2026F-H
FunnelKit and WooCommerce websites using Funnel Builder plugin: Funnel Builder WordPress plugin bug exploited to steal credit cards

Critical Funnel Builder WordPress Plugin Vulnerability Exploited in Payment Card Skimming Attacks

656After Incident
CRITICAL-5
FUNGET1778876719
Critical Funnel Builder WordPress Plugin Vulnerability Exploited in Payment Card Skimming Attacks A severe, unpatched vulnerability in the Funnel Builder WordPress plugin used by over 40,000 websites to customize WooCommerce checkout pages is being actively exploited to inject malicious JavaScript into e-commerce sites. The flaw, which requires no authentication, affects all versions of the plugin prior to 3.15.0.3. Security firm Sansec discovered the attacks, where threat actors exploit an unprotected checkout endpoint to modify the plugin’s global settings. This allows them to insert arbitrary code into the "External Scripts" field, executing malicious payloads on every checkout page. The injected script disguised as a fake Google Tag Manager/Analytics file (analytics-reports[.]com/wss/jquery-lib.js) establishes a WebSocket connection to an attacker-controlled server (wss://protect-wss[.]com/ws). The payload delivers a customized payment card skimmer, harvesting sensitive customer data, including: - Credit card numbers - CVVs - Billing addresses Stolen payment details are typically used for fraudulent transactions or sold on dark web carding markets. FunnelKit, the plugin’s developer, released a patch (version 3.15.0.3) on June 10, 2024, acknowledging the issue in a security advisory and urging users to update immediately. The vendor also advised administrators to review the Settings > Checkout > External Scripts section for unauthorized entries.
INCIDENT DETAILS -
TYPE
Payment Card Skimming
MOTIVATION
Financial gain (fraudulent transactions, dark web carding markets)
IMPACT
Data Compromised: Credit card numbers, CVVs, billing addressesSystems Affected: WordPress websites using Funnel Builder plugin (versions prior to 3.15.0.3)Operational Impact: Malicious JavaScript injection into checkout pagesIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Payment card data (credit card numbers, CVVs, billing addresses)Sensitivity Of Data: HighData Exfiltration: Yes (via WebSocket connection to attacker-controlled server)Personally Identifiable Information: Yes (billing addresses, payment details)
APRIL 2026
660Before Incident
MARCH 2026
658Before Incident
FEBRUARY 2026
657Before Incident
JANUARY 2026
655Before Incident
DECEMBER 2025
653Before Incident
NOVEMBER 2025
651Before Incident
OCTOBER 2025
649Before Incident
SEPTEMBER 2025
647Before Incident
AUGUST 2025
645Before Incident
APRIL 2025
750Before Incident
Breach
06 Apr 2025F-H
WooCommerce

WooCommerce Data Breach

634After Incident
CRITICAL-116
FUN350040925
A cybercriminal under the pseudonym 'Satanic' claims to have breached WooCommerce through a third-party service on April 6, 2025, compromising over 4.4 million records. The breach reportedly includes detailed personal and business information such as contact details, company revenue, employee counts, and technology stacks. Major organizations like NVIDIA, Texas.gov, and NIST are believed to be affected. The breach poses a substantial risk of phishing, social engineering, and intelligence scraping, with the entire database put up for sale by the hacker.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain
IMPACT
Contact detailsCompany revenueEmployee countsTechnology stacks
DATA BREACH
Personal informationBusiness informationNumber Of Records Exposed: 4.4 million

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for F-H ?
?
What was F-H's A.I Rankiteo Cyber Score in June 2026 ?
?
What was F-H's A.I Rankiteo Cyber Score in May 2026 ?
?
What was F-H's A.I Rankiteo Cyber Score in April 2026 ?
?
What was F-H's A.I Rankiteo Cyber Score in March 2026 ?
?
What was F-H's A.I Rankiteo Cyber Score in February 2026 ?
?
What was F-H's A.I Rankiteo Cyber Score in January 2026 ?
?
What was F-H's A.I Rankiteo Cyber Score in December 2025 ?
?
What was F-H's A.I Rankiteo Cyber Score in November 2025 ?
?
What was F-H's A.I Rankiteo Cyber Score in October 2025 ?
?
What was F-H's A.I Rankiteo Cyber Score in September 2025 ?
?
What was F-H's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on F-H's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with F-H ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view F-H's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?