Skip to content
Noroxi

CartFlows records

6 published records for vendor cartflows.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
50%
Median publish → KEV
No record has entered KEV

Records by year

  1. 21
  2. 23
  3. 24

Bar: total · dark part: CISA KEV.

Attack profile

All records

6 records
  • CVE-2024-2322
    27Monitor

    WooCommerce Cart Abandonment Recovery < 1.2.27 - Templates/Abandoned Orders Deletion via CSRF

    MediumCVSS 6.8No exploitEPSS 0%

    cartflows · woocommerce cart abandonment recoveryApr 3, 2024

  • CVE-2024-4632
    25Monitor

    WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scr

    MediumCVSS 6.4No exploitEPSS 0%

    brainstormforce · cartflows – funnel builder & checkout plugin for woocommerceJun 19, 2024

  • WordPress CartFlows Pro Plugin <= 1.11.11 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    cartflows · cartflowsAug 5, 2023

  • Funnel Builder by CartFlows < 1.6.13 - Authenticated Stored XSS via FB Pixel ID and Google Analytics ID

    MediumCVSS 4.8No exploitEPSS 1%

    cartflows · cartflowsJun 1, 2021

  • Funnel Builder <= 1.3.0 - Arbitrary Plugin Activation

    MediumCVSS 4.3No exploitEPSS 1%

    cartflows · cartflowsJun 6, 2023

  • WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce <= 1.5.15 - Cross-Site Request Forgery Bypass

    MediumCVSS 4.3No exploitEPSS 0%

    cartflows · cartflowsJul 1, 2023