header lock
Friday Squid Blogging: Bigfin Squid
16 May 2026
the hacker news
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
17 May 2026

Resources

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

A critical security vulnerability impacting the
Funnel Builder
plugin for WordPress has come under active exploitation in the wild to
inject malicious JavaScript code
into WooCommerce checkout pages with the goal of stealing payment data.

Details of the activity were
published
by Sansec this week. The vulnerability currently does not have an official CVE identifier. It

Related resources