Funnel Builder WordPress plugin bug exploited to steal credit cards

2026-05-16T01:23:26Z6cb29148f90e05b59d32f10a1cf86edda633993697247062d40e245c8eeabc1c
CVE-2026-20182avada-builderburst-statisticsciscocisco-sd-wancredential-theftdenial-of-serviceedgefunnel-buildermicrosoft-exchangenginxnode-ipcnpmopenaipayment-card-theftpwn2ownremote-code-executionremus-infostealersupply-chaintanstackwindows-11woocommercewordpresswordpress-pluginszero-day

What happened

Multiple actively exploited and high-impact security issues reported: a critical Funnel Builder WordPress plugin flaw is being used to inject malicious JavaScript into WooCommerce checkout pages to steal credit cards; the node-ipc npm package was poisoned in a supply-chain attack to steal credentials; Avada Builder and Burst Statistics WordPress plugins contain vulnerabilities enabling credential/data theft and auth bypass; Cisco warned of a critical Catalyst SD‑WAN Controller auth bypass (CVE-2026-20182) exploited in zero‑day attacks; Microsoft disclosed an Exchange zero‑day XSS exploited in-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
6cb29148f90e05b59d32f10a1cf86edda633993697247062d40e245c8eeabc1c
Enrichment time
2026-05-16T01:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.