Funnelkit develops a suite of WordPress-based sales funnel and automation tools including Funnel Builder, Checkout, and Automations products that extend e-commerce and marketing capabilities for small-to-medium business operators. The vendor's vulnerability profile concentrates on web application input-handling and access-control issues, with recurring weakness classes spanning SQL injection, cross-site scripting, missing authorization, and CSRF—typical of plugin-based extensions to WordPress—and a tendency toward public exploit availability. Defenders should monitor this vendor's update cycles for its e-commerce plugins and apply patches promptly to internet-facing WordPress installations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Funnelkit over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1562CRITICAL The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin install | Jun 18, 2025 | 9.8 | 40 | NO | YES |
CVE-2024-9186HIGH The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track- | Nov 14, 2024 | 8.6 | 35 | NO | YES |
CVE-2025-12468MEDIUM The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t | Nov 5, 2025 | 5.3 | 21 | NO | NO |
CVE-2024-47328HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman FunnelKit Automations wp-marketing-automations allows SQL Injection.This | Oct 21, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-50856HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Ch | Dec 28, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-51672HIGH Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3. | Apr 11, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-50857HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, M | Dec 28, 2023 | 7.2 | 20 | NO | NO |
CVE-2025-2203MEDIUM The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | May 15, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-5192MEDIUM The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is vulnerable to St | Jun 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2025-12469MEDIUM The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in | Nov 5, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Funnelkit.
Media articles that mention a CVE ID that affects a product developed by Funnelkit — matched by CVE ID, not by vendor name.