CVE · Medium

CVE-2021-24330 — CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.6.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24330 CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.6.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.6.13 1.6.13 2021-04-29

CVE-2021-24330

The CartFlows funnel builder plugin before version 1.6.13 failed to properly filter the facebook_pixel_id and google_analytics_id configuration options, enabling administrators and other high-privilege users to inject cross-site scripting payloads into these settings. These malicious scripts could then execute either on pages created by the plugin or across the entire website, depending on how the settings were configured.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.