CVE ID :CVE-2026-12978 Published : July 16, 2026, 6 a. m. | 58 minutes ago Description :The FunnelKit WordPress plugin before 3.
15. 0. 6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page.
The affected action is only registered when the Divi /builder is active. Severity: 0.
0 comments
No comments yet. Be the first to start the discussion.