Funnel Builder WordPress plugin bug exploited to steal credit cards
2026-05-16T01:23:26Z•6cb29148f90e05b59d32f10a1cf86edda633993697247062d40e245c8eeabc1c
CVE-2026-20182avada-builderburst-statisticsciscocisco-sd-wancredential-theftdenial-of-serviceedgefunnel-buildermicrosoft-exchangenginxnode-ipcnpmopenaipayment-card-theftpwn2ownremote-code-executionremus-infostealersupply-chaintanstackwindows-11woocommercewordpresswordpress-pluginszero-day
What happened
Multiple actively exploited and high-impact security issues reported: a critical Funnel Builder WordPress plugin flaw is being used to inject malicious JavaScript into WooCommerce checkout pages to steal credit cards; the node-ipc npm package was poisoned in a supply-chain attack to steal credentials; Avada Builder and Burst Statistics WordPress plugins contain vulnerabilities enabling credential/data theft and auth bypass; Cisco warned of a critical Catalyst SD‑WAN Controller auth bypass (CVE-2026-20182) exploited in zero‑day attacks; Microsoft disclosed an Exchange zero‑day XSS exploited in-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 6cb29148f90e05b59d32f10a1cf86edda633993697247062d40e245c8eeabc1c
- Enrichment time
- 2026-05-16T01:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.