CVE-2025-2203

CVE-2025-2203: WooCommerce Checkout & Funnel Builder by FunnelKit < 3.10.2 - Admin+ SQL Injection

Vendor Unknown
Product FunnelKit
Published May 15, 2025
Last update May 16, 2025

CVSS base score

What the vulnerability does

01Description

The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

Key dates

02Disclosure timeline

May 15, 2025 CVE published
May 16, 2025 Record updated