plugin

Woo Cart Abandonment Recovery Vulnerabilities

2 known security issues reported for the Woo Cart Abandonment Recovery WordPress plugin. Most recent disclosed Apr 8, 2026.

1 high 1 medium

Running Woo Cart Abandonment Recovery on your site? Check whether your installed version is affected.

Scan your site free

Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails < 2.1.0 - Authenticated (Shop Manager+) Privilege Escalation

high

The Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.1.0 (exclusive). This makes it possible for authenticated attackers, with Shop Manager-level access and above, to escalate their privileges to that...

CVSS:
7.2
Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Apr 8, 2026

CVE-2026-39470 on NVD →

WooCommerce Cart Abandonment Recovery <= 1.2.26 - Cross-Site Request Forgery to Templates/Abandoned Orders Deletion

medium

The WooCommerce Cart Abandonment Recovery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to delete templates or a...

CVSS:
4.3
Affected:
up to 1.2.26
Fixed in:
1.2.27
Disclosed:
Mar 13, 2024

CVE-2024-2322 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database