WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in CartFlows – Funnel Builder & Checkout Plugin for WooCommerce

1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.

8Reported vulnerabilities
6.6Highest CVSS score
3.1.4Latest version
200,000+Active installs

What to do now

Update CartFlows – Funnel Builder & Checkout Plugin for WooCommerce to 2.2.4 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 11, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-24330 Medium 4.8 0.7% Before 1.6.13 1.6.13 June 1, 2021
CVE-2019-25151 Medium 4.3 0.7% Before 1.3.1 1.3.1 June 7, 2023
CVE-2020-36736 Medium 4.3 0.5% 1.5.15 and earlier 1.5.16 July 1, 2023
CVE-2026-25316 Medium 6.6 0.4% 2.1.19 and earlier 2.2.0 January 26, 2026
CVE-2024-4632 Medium 6.4 0.4% 0 to 2.0.7 (inclusive)
0 to 2.0.7 (inclusive)
2.0.8 June 19, 2024
CVE-2024-29813 Medium 5.5 0.4% 2.0.1 and earlier 2.0.2 March 25, 2024
CVE-2026-39477 Medium 4.3 0.2% 2.2.3 and earlier 2.2.4 March 27, 2026
WF-b9002f6e-4345-4908-9cb8-9841a2458eb7 Low 2.7 Before 1.11.12 1.11.12 June 2, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.