CVE-2026-56052

WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.5 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Blind SQL Injection. This issue affects Funnel Builder by FunnelKit: from n/a through 3.15.0.5.


We have discovered 217 live websites that are affected by CVE-2026-56052.

Run a Free Instant Scan




Affected Software

Product  Funnel Builder
Category Wordpress Plugins
Vulnerable Domains217 live websites (95% of Funnel Builder install base)
Vulnerable Versions
  • from 0 through 3.15.0.5
Vulnerable Versions Count14 versions ( 78% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jun 24, 2026
  • Updated - Jun 24, 2026

Credits

  • Ananda Dhakal | Patchstack (finder)

Website Distribution by Country

Number of websites using CVE-2026-56052
United States108 websites



France13 websites
Germany9 websites
GB8 websites
Netherlands8 websites
South Africa5 websites
Romania5 websites
Bulgaria5 websites
Poland5 websites
Cyprus5 websites

Website Distribution by TLD

Number of websites using CVE-2026-56052
.com136 websites
.nl7 websites
.co.uk6 websites
.fr6 websites
.org5 websites
.pl5 websites
.com.au3 websites
.it3 websites
.net2 websites
.co2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-56052

Top websites that are affected by CVE-2026-56052. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.net United States***,***
*********.com United States***,***
***********.com United States***,***
*****************.com United States***,***
*************.com United States*,***,***
********************.com United States*,***,***
****************.pl Poland*,***,***
*****************.com United States*,***,***
*********.org United States*,***,***
***********.com United States*,***,***
See full domain list

FAQ

CVE-2026-56052 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Funnel Builder
A total of 217 websites have been identified as vulnerable to CVE-2026-56052, based on global website indexing conducted by WebTechSurvey.
The Funnel Builder is affected by the CVE-2026-56052 vulnerability.
Funnel Builder versions up to and including 3.15.0.5 are vulnerable to CVE-2026-56052.