CVE-2026-25316: WordPress CartFlows plugin <= 2.1.19 - PHP Object Injection vulnerability
Published Feb 19, 2026
·Updated
Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This issue affects CartFlows: from n/a through <= 2.1.19.
Affected Software
1 affected component
Brainstorm Force CartFlows<=2.1.19
Event History
Feb 19, 2026
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25316?
The severity of CVE-2026-25316 is rated as high with a score of 7.2 on the CVSS scale.
2
How do I fix CVE-2026-25316?
To fix CVE-2026-25316, upgrade the Brainstorm Force CartFlows plugin to version 2.1.20 or later.
3
What type of vulnerability is CVE-2026-25316?
CVE-2026-25316 is a PHP Object Injection vulnerability that arises from deserialization of untrusted data.
4
Which versions of CartFlows are affected by CVE-2026-25316?
CVE-2026-25316 affects CartFlows versions from its inception through version 2.1.19.
5
What risks does CVE-2026-25316 pose to users?
CVE-2026-25316 poses significant risks including potential remote code execution and unauthorized access to sensitive data.