CVE · Medium

CVE-2020-36736 — CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-36736 CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.5.16 1.5.16 2020-09-26

CVE-2020-36736

The CartFlows plugin for WordPress versions 1.5.15 and earlier are susceptible to cross-site request forgery attacks through the export_json, import_json, and status_logs_file functions due to inadequate nonce verification. An unauthenticated attacker could exploit this vulnerability by crafting a malicious request that, if clicked by an administrator, would allow unauthorized importing or exporting of plugin settings and access to log files. The vulnerability was fixed in version 1.5.16.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.