Funnel Builder WordPress plugin bug exploited to steal credit cards

2026-05-16T07:23:28Z33386594ae948b26c6e8f227d8af016fffad8dea2067cfecdefa3c23f749136e
CVE-2026-20182avada-builderburst-statisticsciscocredentials-theftcredit-card-theftdenial-of-serviceexchangefunnel-builderinfostealernginxnode-ipcnpmopenaipwn2ownremote-code-executionremussd-wansession-theft','edge','passwords-in-memory','driver-rollbacks','supply-chaintanstackwindows-11woocommercewordpresszero-day

What happened

Multiple actively exploited vulnerabilities and supply-chain compromises were reported: a critical Funnel Builder WordPress flaw is being abused to inject JS into WooCommerce checkouts to steal credit cards; Avada Builder and Burst Statistics WordPress plugins have flaws leading to credential/database theft and auth bypass; Cisco Catalyst SD‑WAN Controller auth bypass (CVE-2026-20182) is being exploited for administrative access; Microsoft warned of an Exchange zero-day used against Outlook on the web; and malicious versions of the node-ipc npm package and the broader TanStack supply-chain tro

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
33386594ae948b26c6e8f227d8af016fffad8dea2067cfecdefa3c23f749136e
Enrichment time
2026-05-16T07:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Funnel Builder WordPress plugin bug exploited to steal credit cards · Baitaphish