What is CVE-2026-57373?
CVE-2026-57373 is a Customer Cross Site Scripting (XSS) vulnerability found in Funnel Kit Funnel Builder PRO versions up to 3.15.0.4. An attacker could inject malicious scripts into the application, potentially leading to session hijacking or data theft. Users are strongly advised to update to the latest patched version immediately.
Azərbaycanca: CVE-2026-57373, Funnel Kit Funnel Builder PRO plaginin 3.15.0.4 və daha əvvəlki versiyalarında müştəri tərəfində yaranan Cross Site Scripting (XSS) zəifliyidir. Təcavüzkar xüsusi hazırlanmış skript vasitəsilə istifadəçi məlumatlarını oğurlaya bilər. Təsirə məruz qalan sistemlərdə plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Funnel Kit
FAQ2
Which plugin is affected by CVE-2026-57373?
This vulnerability affects the Funnel Kit Funnel Builder PRO plugin.
What can an attacker do if CVE-2026-57373 is exploited?
An attacker could inject malicious scripts into the application, potentially leading to session hijacking or data theft.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.