Funnel Builder WordPress plugin bug exploited to steal credit cards
2026-05-16T13:23:32Z•44a6e27d80644f2cd577f7b364350306ea613c3b90bff71562ec337183c58a19
avada-builderburst-statisticscisco-sd-wancredential-theftcredit-card-theftdosedgefunnel-buildermicrosoft-exchangenginxnode-ipcnpmopenaipwn2ownrceremus-infostealersupply-chain-attacktanstackteampcpwindows-11woocommercewordpresszero-day
What happened
Multiple high-impact security incidents and active exploits were reported: a critical Funnel Builder WordPress plugin flaw is being exploited to inject malicious JavaScript into WooCommerce checkout pages and steal credit cards; other WordPress plugins (Avada Builder, Burst Statistics) have vulnerabilities enabling credential and admin-account theft. A supply-chain attack compromised the node-ipc npm package and the broader TanStack ecosystem (impacting OpenAI), pushing credential-stealing malware; the REMUS infostealer continues evolving to harvest sessions and tokens. Cisco disclosed an SD‑W
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 44a6e27d80644f2cd577f7b364350306ea613c3b90bff71562ec337183c58a19
- Enrichment time
- 2026-05-16T13:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.