plugin

Cartflows Vulnerabilities

21 known security issues reported for the Cartflows WordPress plugin. Most recent disclosed Mar 27, 2026.

7 medium 1 low

Running Cartflows on your site? Check whether your installed version is affected.

Scan your site free

CartFlows <= 2.2.3 - Missing Authorization

medium

The CartFlows plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.2.3
Fixed in:
2.2.4
Disclosed:
Mar 27, 2026

CVE-2026-39477 on NVD →

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] <= 2.1.19 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This issue affects CartFlows: from n/a through <= 2.1.19.

Affected:
up to 2.1.19
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25316 on NVD →

CartFlows – Checkout & Funnel Builder for WooCommerce <= 2.1.19 - Authenticated (Administrator+) PHP Object Injection

medium

The CartFlows – Checkout & Funnel Builder for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.19 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No...

CVSS:
6.6
Affected:
up to 2.1.19
Fixed in:
2.2.0
Disclosed:
Jan 26, 2026

CVE-2026-25316 on NVD →

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 2.0.8

unknown

[en] The WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This ma...

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Jun 19, 2024

CVE-2024-4632 on NVD →

WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes i...

CVSS:
6.4
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
Jun 18, 2024

CVE-2024-4632 on NVD →

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 2.0.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CartFlows Inc. Funnel Builder by CartFlows allows Stored XSS.This issue affects Funnel Builder by CartFlows: from n/a through 2.0.1.

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Mar 27, 2024

CVE-2024-29813 on NVD →

Funnel Builder by CartFlows <= 2.0.1 - Authenticated (Editor+) Stored Cross-Site Scripting via settings

medium

The WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for a...

CVSS:
5.5
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
Mar 25, 2024

CVE-2024-29813 on NVD →

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 1.5.16

unknown

[en] The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.15. This is due to missing or incorrect nonce validation on the export_json, import_json, and status_logs_file functions. This makes it possible for unauthen...

Affected:
up to 1.5.16
Fixed in:
1.5.16
Disclosed:
Jul 1, 2023

CVE-2020-36736 on NVD →

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 1.3.1

unknown

[en] The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the activate_plugin function in versions up to, and including, 1.3.0. This makes it possible for authenticated attackers to activate any plugin on the vulnerable service.

Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
Jun 7, 2023

CVE-2019-25151 on NVD →

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 1.5.16

unknown
Affected:
up to 1.5.16
Fixed in:
1.5.16
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

CartFlows <= 1.11.11 - Insecure Direct Object Reference to Arbitrary Post Deletion

low

The CartFlows plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.11.11. This is due to the fact that during cart flow deletion/modification, the plugin does not verify that the flow ID provided to the AJAX action is indeed a cart flow id. This makes it possible fo...

CVSS:
2.7
Affected:
up to 1.11.12
Fixed in:
1.11.12
Disclosed:
Jun 2, 2023

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 1.11.12

unknown

The CartFlows plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.11.11. This is due to the fact that during cart flow deletion/modification, the plugin does not verify that the flow ID provided to the AJAX action is indeed a cart flow id. This makes it possible fo...

Affected:
up to 1.11.12
Fixed in:
1.11.12
Disclosed:
Jun 2, 2023

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 1.6.13

unknown

[en] The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS payload in them, which will either be executed on pages generated by the plugin, or the whole w...

Affected:
up to 1.6.13
Fixed in:
1.6.13
Disclosed:
Jun 1, 2021

CVE-2021-24330 on NVD →

Funnel Builder by CartFlows <= 1.6.12 - Authenticated Stored Cross-Site scripting via FB Pixel ID and Google Analytics ID

medium

The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS payload in them, which will either be executed on pages generated by the plugin, or the whole websit...

CVSS:
4.8
Affected:
up to 1.6.13
Fixed in:
1.6.13
Disclosed:
May 17, 2021

CVE-2021-24330 on NVD →

WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce <= 1.5.15 - Cross-Site Request Forgery Bypass

medium

The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.15. This is due to missing or incorrect nonce validation on the export_json, import_json, and status_logs_file functions. This makes it possible for unauthenticat...

CVSS:
4.3
Affected:
up to 1.5.16
Fixed in:
1.5.16
Disclosed:
Sep 26, 2020

CVE-2020-36736 on NVD →

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 1.5.16

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Funnel Builder by CartFlows plugin (versions <= 1.5.15).

Affected:
up to 1.5.16
Fixed in:
1.5.16
Disclosed:
Sep 16, 2020

Funnel Builder <= 1.3.0 - Arbitrary Plugin Activation

medium

The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the activate_plugin function in versions up to, and including, 1.3.0. This makes it possible for authenticated attackers to activate any plugin on the vulnerable service.

CVSS:
5.4
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
Nov 7, 2019

CVE-2019-25151 on NVD →

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 1.3.1

unknown

The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the activate_plugin function in versions up to, and including, 1.3.0. This makes it possible for authenticated attackers to activate any plugin on the vulnerable service.

Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
Nov 7, 2019

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 1.5.16

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 1.5.16
Fixed in:
1.5.16

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 1.3.1

unknown

Issue allowing any authenticated user to active a plugin on the blog.

Affected:
up to 1.3.1
Fixed in:
1.3.1

CartFlows &#8211; Checkout &amp; Funnel Builder for WooCommerce [cartflows] < 1.5.16

unknown

NinTechNet discovered multiple WordPress plugins and themes vulnerable to Cross-Site Request Forgery (CSRF). The items only check the CSRF nonce if it has been provided, making them vulnerable to CSRF attacks if the nonce is removed. This is due to the confusing use of logic operators when verifying the nonces.

Affected:
up to 1.5.16
Fixed in:
1.5.16

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database