CVE-2025-10567: Unknown Funnelkit

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.

Affected products

  • Unknown Funnelkit: before 3.12.0.1 (fixed in 3.12.0.1)

Published 2025-11-05. Last modified 2026-06-17.