PLUGIN SECURITY
Is Cartflows safe?
1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.
What this plugin does
- Slug:
cartflows - Author: Brainstorm Force
- 200000+ active installs
- 96/100 rating (504 reviews on wordpress.org)
- 10854203 all-time downloads
- On WordPress.org since 2018-11-30
lead generationorder bumpsales funnelsupsellwoocommerce
Maintenance status
- Latest known version: 3.1.3
- Last updated: 2026-08-24 10:53am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.2+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
15 known CVEs on file for Cartflows. Reported between 2019 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-39477 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.2.4 | — | Medium 4.3 | < 2.2.4 | 2.2.4 | 2026-03-27 | ✓ fixed in latest |
| CVE-2026-25316 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.2.0 | Deserialization of Untrusted Data | High 7.2 | < 2.2.0 | 2.2.0 | 2026-01-26 | ✓ fixed in latest |
| CVE-2024-4632 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.0.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.0.8 | 2.0.8 | 2024-06-18 | ✓ fixed in latest |
| CVE-2024-29813 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.0.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 2.0.2 | 2.0.2 | 2024-03-25 | ✓ fixed in latest |
| CVE-2021-4342 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 | — | Unknown | < 1.5.16 | 1.5.16 | 2023-06-07 | ✓ fixed in latest |
| — | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.11.12 | — | Unknown | < 1.11.12 | 1.11.12 | 2023-06-02 | ✓ fixed in latest |
| CVE-2021-24330 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.6.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 1.6.13 | 1.6.13 | 2021-04-29 | ✓ fixed in latest |
| CVE-2020-36736 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.5.16 | 1.5.16 | 2020-09-26 | ✓ fixed in latest |
+ 7 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 | — | Unknown | < 1.5.16 | 1.5.16 | 2020-09-16 | ✓ fixed in latest |
| CVE-2019-25151 | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.3.1 | Improper Privilege Management | Medium 5.4 | < 1.3.1 | 1.3.1 | 2019-11-07 | ✓ fixed in latest |
| — | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 | — | Unknown | < 1.5.16 | 1.5.16 | — | ✓ fixed in latest |
| — | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.3.1 | — | Unknown | < 1.3.1 | 1.3.1 | — | ✓ fixed in latest |
| — | CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 1.5.16 | — | Unknown | < 1.5.16 | 1.5.16 | — | ✓ fixed in latest |
| CVE-2019-25151 | Funnel Builder by CartFlows < 1.3.1 - Authenticated Arbitrary Plugin Activation | — | Unknown | < 1.3.1 | 1.3.1 | — | ✓ fixed in latest |
| CVE-2020-36707, CVE-2021-4417, CVE-2020-36752, CVE-2020-36757, CVE-2020-36756, CVE-2020-36761, CVE-2020-36760, CVE-2020-36760 | Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF) | — | Unknown | < 1.5.16 | 1.5.16 | — | ✓ fixed in latest |
How to fix it
Keep Cartflows updated — 3.1.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Hostinger Reach – AI-Powered Email Marketing for WordPress — 1000000+ active installs — 100/100 (6) — max PHP 8.4
- Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress — 50000+ active installs — 92/100 (1168) — max PHP 8.4
- Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation — 30000+ active installs — 86/100 (152) — max PHP <8.0
- Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content — 20000+ active installs — 96/100 (209) — max PHP 8.4
- Icegram Engage – Popups, Optins, CTAs & Lead Generation — 10000+ active installs — 94/100 (369)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.