CVE Database /
CVE-2026-39477
CVE · Medium
CVE-2026-39477 — CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.2.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-39477
|
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.2.4 |
— |
Medium
4.3
|
< 2.2.4
|
2.2.4 |
2026-03-27 |
—
|
CVE-2026-39477
The CartFlows plugin for WordPress has a security flaw that allows unauthorized access when the version is 2.2.3 or earlier. Authenticated users with at least contributor permissions can exploit this by performing actions they should not be able to, due to a missing capability check in certain functions.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings