Ravie LakshmananMay 16, 2026Vulnerability / Website Security
A critical security vulnerability impacting the
Funnel Builder
plugin for WordPress has come under active exploitation in the wild to
inject malicious JavaScript code
Funnel Builder flaw hits 40,000+ stores; fake GTM skimmers steal checkout payment data before patch 3.15.0.3.
Ravie LakshmananMay 16, 2026Vulnerability / Website Security
A critical security vulnerability impacting the
Funnel Builder
plugin for WordPress has come under active exploitation in the wild to
inject malicious JavaScript code

Funnel Builder WordPress plugin bug exploited to steal credit cards

Avada Builder WordPress plugin flaws allow site credential theft

Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin

Cookie thieves caught stealing dev secrets via fake Claude Code installers

Security | Ecommerce tips & how tos - Shopify

GitHub Flaw Reveals Dangers of Implicit Trust

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution

OpenAI caught in TanStack npm supply chain chaos after employee devices compromised

822K Downloads at Risk: Malicious node-ipc Versions Spotted Stealing AWS and Private Keys