PoC Index

CVE-2026-12978

HIGH 7.1EPSS 0.3%

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active.

CVSS v3.1
7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS
0.28% chance of exploitation in the next 30 days, 20th percentile
Published
2026-07-16

Proof-of-concept exploits (1)

References

Related