Impact
A vulnerability in WordPress CartFlows plugin versions 3.2.0 and earlier allows a contributor to execute arbitrary code on the host system. The flaw enables the attacker to run malicious scripts, compromising the confidentiality, integrity, and availability of the affected WordPress installation. The weakness is classified as CWE-98, reflecting the improper handling of remote code execution requests.
Affected Systems
The flaw affects the Brainstorm Force CartFlows plugin for WordPress. All installations running version 3.2.0 or earlier are vulnerable; upgrading to 3.2.1 or later resolves the issue.
Risk and Exploitability
The CVSS score of 8.8 designates a high severity, indicating significant impact on systems if exploited. EPSS data is not currently available, and the vulnerability is not listed in the CISA KEV catalog at this time. The likely attack vector is through the plugin’s contributor interface, where permission to inject code can be abused if the contributor role is over‑privileged or compromised. Successful exploitation would allow a remote attacker to execute arbitrary code with the privileges of the WordPress site user.
OpenCVE Enrichment