FunnelCockpit
FunnelCockpit has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 6.1 out of 10. 2025 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).
Every one of the 3 issues recorded for FunnelCockpit has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. FunnelCockpit is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-6588FunnelCockpit <= 1.4.3 - Reflected Cross-Site Scripting via `error` Parameter
Read the full analysisVulnerability Records

FunnelCockpit
Author
FunnelCockpit
FunnelCockpit helps you publish FunnelCockpit funnels and landing pages on your WordPress site. Connect your FunnelCockpit account, select the funnel page you want to use, and make it available through WordPress. Key features Funnel page publishing – Connect FunnelCockpit pages to WordPress URLs Landing page integration – Publish landing pages from your FunnelCockpit account Split test support – Serve FunnelCockpit split test pages through WordPress Caching – Cache fetched funnel page content for faster delivery WordPress front page support – Use a funnel page as the WordPress front page Mobile-ready output – FunnelCockpit pages remain optimized for mobile devices Best for Online marketers Businesses Agencies E-commerce stores Course providers FunnelCockpit users who want to publish funnels on WordPress More information: https://funnelcockpit.com/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C