What is CVE-2026-57374?
CVE-2026-57374 is an unauthenticated Cross Site Scripting (XSS) vulnerability found in Funnel Kit Funnel Builder PRO up to version 3.15.0.7. This flaw allows unauthenticated visitors to inject malicious scripts into the website. It is recommended to deactivate the plugin until a security patch is applied.
Azərbaycanca: CVE-2026-57374, Funnel Kit Funnel Builder PRO plaginində 3.15.0.7 versiyasına qədər aşkarlanmış autentifikasiyasız Cross Site Scripting (XSS) zəifliyidir. Bu boşluq təsdiqlənməmiş ziyarətçilərə zərərli skriptləri veb-səhifəyə daxil etməyə imkan verir. Plaginni təhlükəsizlik yaması tətbiq olunana qədər deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Funnel Kit
FAQ2
Which versions of the Funnel Kit Funnel Builder PRO plugin are affected by CVE-2026-57374?
This unauthenticated XSS vulnerability affects Funnel Kit Funnel Builder PRO up to version 3.15.0.7.
What is recommended to mitigate CVE-2026-57374 until a security patch is applied?
It is recommended to deactivate the plugin until a security patch is applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.