Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-12978 - FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form

CVE ID :CVE-2026-12978 Published : July 16, 2026, 6 a. m. | 58 minutes ago Description :The FunnelKit WordPress plugin before 3.

15. 0. 6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page.

The affected action is only registered when the Divi /builder is active. Severity: 0.

Originally reported by CVE Recent
0 comments

0 comments

Posting as StoicQuokka340
0/1000

No comments yet. Be the first to start the discussion.