Cartflows is a WordPress plugin focused on conversion optimization and cart-recovery functionality, with its vulnerability exposure centered on the core Cartflows plugin and its WooCommerce Cart Abandonment Recovery feature. The recurring weakness classes—cross-site request forgery, cross-site scripting, and improper privilege management—are characteristic of web-application plugins operating within the WordPress ecosystem and reflect the authentication and input-handling demands of e-commerce extensions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cartflows over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2322MEDIUM The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admins delete a | Apr 3, 2024 | 6.8 | 19 | NO | NO |
CVE-2021-24330MEDIUM The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, a | Jun 1, 2021 | 4.8 | 19 | NO | NO |
CVE-2023-36686MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CartFlows Pro plugin <= 1.11.11 versions. | Aug 5, 2023 | 6.1 | 17 | NO | NO |
CVE-2020-36736MEDIUM The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.15. This is due to mis | Jul 1, 2023 | 4.3 | 16 | NO | NO |
CVE-2019-25151MEDIUM The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the activate_plugin function in versions up to, and including, 1. | Jun 7, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cartflows.
Media articles that mention a CVE ID that affects a product developed by Cartflows — matched by CVE ID, not by vendor name.