Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
2026-05-16T19:24:04Z•4b625c15678ea762e6e60fc5768693145eb9c931a6acdffe840aafb632439922
active-exploitationbackdoorbotnetcisa-kevcredential-theftcritical-vulnerabilitiescveincident-responselinux-kernelmalicious-packagesnation-statenpmp2p-botnetprivilege-escalationrcerubygemssupply-chainweb-skimmingwoocommercewordpress
What happened
This collection of reports highlights a high-impact week of active exploitation, supply‑chain abuse, and critical vulnerability disclosures. Key incidents include: a Funnel Builder WordPress plugin flaw being actively used to inject JavaScript for WooCommerce checkout skimming (no CVE yet); Cisco Catalyst SD‑WAN Controller authentication bypass (CVE-2026-20182, CVSS 10.0) added to CISA KEV and exploited to gain admin access; on‑prem Microsoft Exchange spoofing/XSS vulnerability (CVE-2026-42897, CVSS 8.1) being exploited via crafted email; multiple high-severity product flaws and zero-days (Ex:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 4b625c15678ea762e6e60fc5768693145eb9c931a6acdffe840aafb632439922
- Enrichment time
- 2026-05-16T19:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.