Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
WPFunnels

WPFunnels Vendor Cyber Rating & Cyber Score

getwpfunnels.com

WPFunnels is one of the easiest WordPress solutions to create funnels and automate marketing for your business. Join our growing community: https://www.facebook.com/getwpfunnels It is a renounced sales funnel builder in WordPress that you can use to visually plan your funnel steps and run lead generation or sales campaigns with special offers such as order bumps, one-click upsells, special discounts, conditional offers, and many more. Besides the sales funnel builder, the team also developed an email marketing automation tool called Mail Mint, which will let you collect & manage leads, run email campaigns, set up automation workflows, and set up email automation for your funnels. Whether you are a digital creator, an online coach or


WPFunnels A.I CyberSecurity Scoring

WPFunnels
Company Information
Website:https://getwpfunnels.com/
Employees number:3
Number of followers:82
NAICS:5112
Industry Type:Software Development
Homepage:getwpfunnels.com
WPFunnels Risk Score (AI oriented)
Between 700 and 749
logo
WPFunnelsSoftware Development
Updated:
15/05/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
WPFunnels Global Score (TPRM)
xxxx
logo
WPFunnelsSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

WPFunnels
WPFunnelsModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
749Before Incident
JUNE 2026
749Before Incident
MAY 2026
751Before Incident
Vulnerability
14 May 2026WPFunnels
FunnelKit and WooCommerce websites using Funnel Builder plugin: Funnel Builder WordPress plugin bug exploited to steal credit cards

Critical Funnel Builder WordPress Plugin Vulnerability Exploited in Payment Card Skimming Attacks

749After Incident
CRITICAL-2
FUNGET1778876719
Critical Funnel Builder WordPress Plugin Vulnerability Exploited in Payment Card Skimming Attacks A severe, unpatched vulnerability in the Funnel Builder WordPress plugin used by over 40,000 websites to customize WooCommerce checkout pages is being actively exploited to inject malicious JavaScript into e-commerce sites. The flaw, which requires no authentication, affects all versions of the plugin prior to 3.15.0.3. Security firm Sansec discovered the attacks, where threat actors exploit an unprotected checkout endpoint to modify the plugin’s global settings. This allows them to insert arbitrary code into the "External Scripts" field, executing malicious payloads on every checkout page. The injected script disguised as a fake Google Tag Manager/Analytics file (analytics-reports[.]com/wss/jquery-lib.js) establishes a WebSocket connection to an attacker-controlled server (wss://protect-wss[.]com/ws). The payload delivers a customized payment card skimmer, harvesting sensitive customer data, including: - Credit card numbers - CVVs - Billing addresses Stolen payment details are typically used for fraudulent transactions or sold on dark web carding markets. FunnelKit, the plugin’s developer, released a patch (version 3.15.0.3) on June 10, 2024, acknowledging the issue in a security advisory and urging users to update immediately. The vendor also advised administrators to review the Settings > Checkout > External Scripts section for unauthorized entries.
INCIDENT DETAILS -
TYPE
Payment Card Skimming
MOTIVATION
Financial gain (fraudulent transactions, dark web carding markets)
IMPACT
Data Compromised: Credit card numbers, CVVs, billing addressesSystems Affected: WordPress websites using Funnel Builder plugin (versions prior to 3.15.0.3)Operational Impact: Malicious JavaScript injection into checkout pagesIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Payment card data (credit card numbers, CVVs, billing addresses)Sensitivity Of Data: HighData Exfiltration: Yes (via WebSocket connection to attacker-controlled server)Personally Identifiable Information: Yes (billing addresses, payment details)
APRIL 2026
751Before Incident
MARCH 2026
751Before Incident
FEBRUARY 2026
751Before Incident
JANUARY 2026
751Before Incident
DECEMBER 2025
751Before Incident
NOVEMBER 2025
751Before Incident
OCTOBER 2025
751Before Incident
SEPTEMBER 2025
751Before Incident
AUGUST 2025
751Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for WPFunnels ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in June 2026 ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in May 2026 ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in April 2026 ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in March 2026 ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in February 2026 ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in January 2026 ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in December 2025 ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in November 2025 ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in October 2025 ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in September 2025 ?
?
What was WPFunnels's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on WPFunnels's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with WPFunnels ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view WPFunnels's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?