Executive brief
CartFlows is a popular WordPress plugin used to create sales funnels and checkout experiences for e-commerce sites. A security flaw in versions 2.2.3 and earlier allows users with low-level access (such as contributors) to bypass intended security restrictions. This could lead to unauthorized access to certain administrative functions or data, potentially compromising the integrity of the sales funnel configuration.
Technical details
A Broken Access Control (Missing Authorization) vulnerability exists in the Brainstorm Force CartFlows plugin for WordPress. The flaw, classified as CWE-862, stems from insufficient validation of user permissions within certain plugin functions. An attacker authenticated with 'Contributor' or higher privileges can exploit this over the network without user interaction to perform actions or access data they are not authorized to reach. The issue is resolved in version 2.2.4, which introduces proper authorization checks.
Affected products
- Brainstorm Force CartFlows <= 2.2.3
Timeline
- 2026-02-25: other: Vulnerability reported by researcher
- 2026-03-27: advisory: Patchstack published initial advisory
- 2026-04-08: disclosed: CVE published to NVD
- 2026-04-08: patched: Version 2.2.4 released to address the issue