Sceawere

Vulnerability Detail

CVE-2026-96837UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CartFlows Contributor Remote Code Execution

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
Brainstorm Force
Product
CartFlows
Attack Type
CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-30T13:17:33.673Z",
  "pubdate": "2026-09-30T13:17:33.673Z",
  "executiveSummary": "A critical vulnerability exists in CartFlows versions 3.2.0 and below, allowing authenticated users with Contributor-level privileges to achieve Remote Code Execution (RCE) on the underlying host server.\nThe vulnerability stems from improper input validation and insecure handling of user-supplied data, which facilitates the execution of arbitrary PHP code.\nSuccessful exploitation grants an attacker full control over the WordPress application, potentially leading to unauthorized data access, site defacement, or total system compromise.\nThe attack is restricted to authenticated users with the Contributor role, which serves as a significant privilege requirement, though the impact remains severe due to the resulting server-level execution.\nThis flaw exposes the host environment to persistent backdoors and unauthorized administrative manipulation.",
  "technicalDetails": "The vulnerability resides within the CartFlows framework's handling of user-submitted configurations or file inputs, where the application fails to adequately sanitize or restrict content provided by Contributor-level accounts.\nIn affected versions (<= 3.2.0), the application's internal logic processes these inputs without rigorous validation against a whitelist of safe file types or code structures. Because Contributor accounts are permitted to perform specific actions that trigger these processing routines, they can inject malicious PHP code into the environment.\nThe attack flow commences with the attacker authenticated as a Contributor. The user exploits a vulnerable function or endpoint that handles configuration or template imports. By crafting a specific payload containing malicious PHP instructions, the attacker submits it through the identified vulnerable component.\nThe system, lacking sufficient security controls, proceeds to store or execute the injected code path. This effectively bypasses standard WordPress permission models, as the application interprets the malicious payload as trusted logic.\nOnce the PHP execution is triggered, the attacker gains the ability to execute arbitrary commands with the privileges of the web server process (e.g., www-data). This facilitates post-exploitation activities including, but not limited to, the installation of web shells, exfiltration of sensitive database configurations, and lateral movement within the hosting environment.\nThe vulnerability is primarily rooted in the lack of robust server-side sanitization and the absence of file integrity checks during the handling of imported components. Since the exploitation occurs at the application layer, network exposure is inherent to any publicly accessible WordPress installation running the affected CartFlows version, provided an account with at least Contributor-level access is compromised or malicious in intent."
}
CVE-2026-96837: CartFlows Contributor Remote Code Execution (HIGH Severity, CVSS: 8.8) | Sceawere