PLUGIN SECURITY

Is Cartflows safe?

1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.

What this plugin does

  • Slug: cartflows
  • Author: Brainstorm Force
  • 200000+ active installs
  • 96/100 rating (504 reviews on wordpress.org)
  • 10854203 all-time downloads
  • On WordPress.org since 2018-11-30

lead generationorder bumpsales funnelsupsellwoocommerce

Maintenance status

  • Latest known version: 3.1.3
  • Last updated: 2026-08-24 10:53am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.2+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

15 known CVEs on file for Cartflows. Reported between 2019 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-39477 CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.2.4 Medium 4.3 < 2.2.4 2.2.4 2026-03-27 ✓ fixed in latest
CVE-2026-25316 CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.2.0 Deserialization of Untrusted Data High 7.2 < 2.2.0 2.2.0 2026-01-26 ✓ fixed in latest
CVE-2024-4632 CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.0.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.0.8 2.0.8 2024-06-18 ✓ fixed in latest
CVE-2024-29813 CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.0.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 2.0.2 2.0.2 2024-03-25 ✓ fixed in latest
CVE-2021-4342 CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 Unknown < 1.5.16 1.5.16 2023-06-07 ✓ fixed in latest
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.11.12 Unknown < 1.11.12 1.11.12 2023-06-02 ✓ fixed in latest
CVE-2021-24330 CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.6.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.6.13 1.6.13 2021-04-29 ✓ fixed in latest
CVE-2020-36736 CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.5.16 1.5.16 2020-09-26 ✓ fixed in latest
+ 7 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 Unknown < 1.5.16 1.5.16 2020-09-16 ✓ fixed in latest
CVE-2019-25151 CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.3.1 Improper Privilege Management Medium 5.4 < 1.3.1 1.3.1 2019-11-07 ✓ fixed in latest
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 Unknown < 1.5.16 1.5.16 ✓ fixed in latest
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.3.1 Unknown < 1.3.1 1.3.1 ✓ fixed in latest
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 Unknown < 1.5.16 1.5.16 ✓ fixed in latest
CVE-2019-25151 Funnel Builder by CartFlows < 1.3.1 - Authenticated Arbitrary Plugin Activation Unknown < 1.3.1 1.3.1 ✓ fixed in latest
CVE-2020-36707, CVE-2021-4417, CVE-2020-36752, CVE-2020-36757, CVE-2020-36756, CVE-2020-36761, CVE-2020-36760, CVE-2020-36760 Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF) Unknown < 1.5.16 1.5.16 ✓ fixed in latest

How to fix it

Keep Cartflows updated — 3.1.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.