Funnel Builder plugin versions before 3.15.0.3 allowed unauthenticated attackers to inject malicious JavaScript into WooCommerce checkout pages, enabling card data theft from 40,000 stores.
Watch on ThreatNoir: https://threatnoir.com/show/wordpress...
Sources cited:
Funnel Builder WordPress plugin bug exploited to steal credit cards: https://www.bleepingcomputer.com/news...