CVE-2026-39477: WordPress CartFlows plugin <= 2.2.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartFlows: from n/a through <= 2.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress CartFlows pluginto a version that resolves this vulnerability.Fixed in 2.2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39477?
CVE-2026-39477 has a severity rating of medium, scoring 4.3 on the CVSS scale.
How do I fix CVE-2026-39477?
To fix CVE-2026-39477, update the Brainstorm Force CartFlows plugin to the latest version beyond 2.2.3.
What impact does CVE-2026-39477 have on my WordPress site?
CVE-2026-39477 can lead to unauthorized access to sensitive areas of your site due to broken access control.
Which versions of CartFlows are affected by CVE-2026-39477?
CVE-2026-39477 affects all versions of CartFlows from n/a through 2.2.3.
Is my site at risk if I use an affected version of CartFlows?
Yes, if you are using an affected version of CartFlows, your site is at risk of exploitation due to the broken access control.