Software intelligence
Important: Funnel Builder Pro appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
3
Latest advisory
7 July 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
funnel-builder-pro
Plugin
This catalog lists 3 known advisories affecting Funnel Builder Pro. The most recent was published on 7 July 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
FunnelKit Funnel Builder Pro <= 3.15.0.7 - Unauthenticated Stored Cross-Site Scripting
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 7 July 2026
FunnelKit Funnel Builder Pro <= 3.15.0.4 - Authenticated (Customer+) Stored Cross-Site Scripting
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 7 July 2026
Funnel Kit Funnel Builder PRO <= 3.4.5 Authenticated(Contributor+) Stored Cross-Site Scripting via allow_iframe_tag_in_post
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 28 August 2024
Known Funnel Builder Pro advisories published by month.
CVE-2026-57374 · Published 7 July 2026
Affected versions: ≤ 3.15.0.7
CVE-2026-57373 · Published 7 July 2026
Affected versions: ≤ 3.15.0.4
CVE-2024-1056 · Published 28 August 2024
Affected versions: ≤ 3.4.5
SiteRespond Defence matches your installed Funnel Builder Pro version against this catalog when the Defence plugin is connected to your WordPress site.