Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Funnelkit

First CVE: Aug 22, 2022Active for: 4 yearsTotal CVEs: 16
36.7
VTI Score
Medium

Funnelkit develops a suite of WordPress-based sales funnel and automation tools including Funnel Builder, Checkout, and Automations products that extend e-commerce and marketing capabilities for small-to-medium business operators. The vendor's vulnerability profile concentrates on web application input-handling and access-control issues, with recurring weakness classes spanning SQL injection, cross-site scripting, missing authorization, and CSRF—typical of plugin-based extensions to WordPress—and a tendency toward public exploit availability. Defenders should monitor this vendor's update cycles for its e-commerce plugins and apply patches promptly to internet-facing WordPress installations; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Funnelkit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2022
3 years ago
Most Recent CVE
Nov 5, 2025
262 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-1562CRITICAL
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin install
Jun 18, 20259.840NOYES
CVE-2024-9186HIGH
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-
Nov 14, 20248.635NOYES
CVE-2025-12468MEDIUM
The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t
Nov 5, 20255.321NONO
CVE-2024-47328HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman FunnelKit Automations wp-marketing-automations allows SQL Injection.This
Oct 21, 20247.221NONO
CVE-2023-50856HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Ch
Dec 28, 20237.221NONO
CVE-2023-51672HIGH
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
Apr 11, 20247.520NONO
CVE-2023-50857HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, M
Dec 28, 20237.220NONO
CVE-2025-2203MEDIUM
The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
May 15, 20256.119NONO
CVE-2024-5192MEDIUM
The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is vulnerable to St
Jun 29, 20245.418NONO
CVE-2025-12469MEDIUM
The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in
Nov 5, 20254.317NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
63%
31%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (75.0%)
Unknown0 (0.0%)
Required4 (25.0%)
Privileges Required
Low8 (50.0%)
High3 (18.8%)
None5 (31.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
12.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Funnelkit.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Funnelkit — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Funnelkit's Products

View all 3 CNAs →

Top CWEs