Medium 4.3
2026-04-08< 2.2.4
CVE-2026-39477
Minimum safe version
2.2.4
Update to 2.2.4 or later to address 14 fixable vulnerabilities
CVE-2026-39477
CVE-2026-25316
CVE-2024-4632
CVE-2024-29813
CartFlows <= 1.11.11 - Insecure Direct Object Reference to Arbitrary Post Deletion
CVE-2020-36736
CVE-2021-4342
CVE-2019-25151
Funnel Builder <= 1.3.0 - Arbitrary Plugin Activation
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
Funnel Builder by CartFlows < 1.3.1 - Authenticated Arbitrary Plugin Activation
Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF)
WordPress Funnel Builder by CartFlows plugin <= 1.5.15 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24330