The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress has a security vulnerability in versions up to, and including, 1.5.15. This means that someone could potentially perform malicious actions without a site administrator knowing, such as exporting/importing settings and triggering logs. This is because the plugin does not have a safety measure called a nonce validation for certain functions.