CVE-2026-47100
Last modified
CVE-2026-47100 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-47100?
How severe is CVE-2026-47100?
How do I fix CVE-2026-47100?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-47090Claude HUD through 0.0.12, patched in commit 234d9aa, constr…4.6
- CVE-2026-47091Claude HUD through 0.0.12, patched in commit 234d9aa, contai…4.8
- CVE-2026-47092Claude HUD through 0.0.12, patched in commit 234d9aa, contai…7.8
- CVE-2026-47093Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-47099TeleJSON prior to 6.0.0 contains a DOM-based cross-site scri…6.1
- CVE-2026-4710Incorrect boundary conditions in the Audio/Video component. …9.8
- CVE-2026-47101LiteLLM prior to 1.83.14 allows an authenticated internal_us…8.8
- CVE-2026-47102LiteLLM prior to 1.83.10 allows a user to modify their own u…8.8
- CVE-2026-47103Python StateMachine versions 3.0.0 before 3.2.0 contains a r…9.8
- CVE-2026-47104libusb before version 1.0.30 contains a one-byte out-of-boun…5.5
- CVE-2026-47105Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-47106Ellucian Banner Self-Service before the April T2 release (20…5.4
Are you affected by CVE-2026-47100?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
