CVE-2026-57816

WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.15.0.8.


We have discovered 235 live websites that are affected by CVE-2026-57816.

Run a Free Instant Scan




Affected Software

Product  Funnel Builder
Category Wordpress Plugins
Vulnerable Domains235 live websites (100% of Funnel Builder install base)
Vulnerable Versions
  • from 0 through 3.15.0.8
Vulnerable Versions Count15 versions ( 83% of all versions)



Details

  • Published - Jul 13, 2026
  • Updated - Jul 13, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-57816
United States119 websites



France14 websites
GB10 websites
Netherlands9 websites
Germany9 websites
South Africa5 websites
Romania5 websites
Italy5 websites
Bulgaria5 websites
Poland5 websites

Website Distribution by TLD

Number of websites using CVE-2026-57816
.com148 websites
.nl8 websites
.co.uk6 websites
.org6 websites
.fr6 websites
.pl5 websites
.net3 websites
.it3 websites
.com.au3 websites
.co2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-57816

Top websites that are affected by CVE-2026-57816. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**,***
********************.com United States**,***
*************.net United States***,***
*********.com United States***,***
***********.com United States***,***
******.nl Netherlands***,***
********.com United States***,***
*****************.com United States***,***
*************.com United States*,***,***
********************.com United States*,***,***
See full domain list

FAQ

A total of 235 websites have been identified as vulnerable to CVE-2026-57816, based on global website indexing conducted by WebTechSurvey.
The Funnel Builder is affected by the CVE-2026-57816 vulnerability.
Funnel Builder versions up to and including 3.15.0.8 are vulnerable to CVE-2026-57816.