Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails < 2.1.0 - Authenticated (Shop Manager+) Privilege Escalation
high
The Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.1.0 (exclusive). This makes it possible for authenticated attackers, with Shop Manager-level access and above, to escalate their privileges to that...
- CVSS:
- 7.2
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.0
- Disclosed:
- Apr 8, 2026
CVE-2026-39470 on NVD →
WooCommerce Cart Abandonment Recovery <= 1.2.26 - Cross-Site Request Forgery to Templates/Abandoned Orders Deletion
medium
The WooCommerce Cart Abandonment Recovery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to delete templates or a...
- CVSS:
- 4.3
- Affected:
- up to 1.2.26
- Fixed in:
- 1.2.27
- Disclosed:
- Mar 13, 2024
CVE-2024-2322 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database