Abandoned Cart Lite for WooCommerce <= 6.8.0 - Authenticated (Shop manager+) Stored Cross-Site Scripting
medium
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary...
- CVSS:
- 4.4
- Affected:
- up to 6.8.0
- Fixed in:
- 6.8.1
- Disclosed:
- Jul 24, 2026
CVE-2026-65557 on NVD →
Abandoned Cart Lite for WooCommerce <= 6.8.0 - Cross-Site Request Forgery
medium
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.8.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged reques...
- CVSS:
- 4.3
- Affected:
- up to 6.8.0
- Fixed in:
- 6.8.1
- Disclosed:
- Jun 26, 2026
CVE-2026-57637 on NVD →
Abandoned Cart Lite for WooCommerce <= 6.8.1 - Unauthenticated Privilege Escalation via Weak Recovery Link
critical
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.8.1. This makes it possible for unauthenticated attackers to gain access to other user's accounts, including administrators.
- CVSS:
- 9.8
- Affected:
- up to 6.8.1
- Fixed in:
- 6.8.2
- Disclosed:
- Jun 25, 2026
CVE-2026-12585 on NVD →
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.16.2
unknown
[en] Missing Authorization vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Abandoned Cart Lite for WooCommerce: from n/a through 5.16.1.
- Affected:
- up to 5.16.2
- Fixed in:
- 5.16.2
- Disclosed:
- Dec 13, 2024
CVE-2023-41671 on NVD →
Abandoned Cart Lite for WooCommerce <= 5.16.1 - Cross-Site Request Forgery
medium
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.16.1. This is due to missing or incorrect nonce validation on the functions corresponding to AJAX actions. This makes it possible for unauthenticated attackers to dismiss noti...
- CVSS:
- 5.3
- Affected:
- up to 5.16.1
- Fixed in:
- 5.16.2
- Disclosed:
- Dec 1, 2023
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.16.2
unknown
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.16.1. This is due to missing or incorrect nonce validation on the functions corresponding to AJAX actions. This makes it possible for unauthenticated attackers to dismiss noti...
- Affected:
- up to 5.16.2
- Fixed in:
- 5.16.2
- Disclosed:
- Dec 1, 2023
Abandoned Cart Lite for WooCommerce <= 5.16.1 - Missing Authorization via multiple AJAX functions
medium
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple AJAX functions in versions up to, and including, 5.16.1. This makes it possible for authenticated attackers, with subscriber-level access and ab...
- CVSS:
- 5.4
- Affected:
- up to 5.16.1
- Fixed in:
- 5.16.2
- Disclosed:
- Nov 28, 2023
CVE-2023-41671 on NVD →
Abandoned Cart Lite for WooCommerce <= 5.16.0 - Improper Authorization via wcal_preview_emails
low
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wcal_preview_emails function in all versions up to and including 5.16.0. This makes it possible for unauthenticated attackers to preview emails, granted they are able to obt...
- CVSS:
- 3.7
- Affected:
- up to 5.16.1
- Fixed in:
- 5.16.1
- Disclosed:
- Nov 21, 2023
Abandoned Cart Lite for WooCommerce <= 5.16.0 - Improper Authorization via wcal_delete_expired_used_coupon_code
low
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to invalid logic in the capability check present in the wcal_delete_expired_used_coupon_code function in all versions up to and including 5.16.0. This makes it possible for authenticated attackers with subscriber...
- CVSS:
- 3.1
- Affected:
- up to 5.16.1
- Fixed in:
- 5.16.1
- Disclosed:
- Nov 21, 2023
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.16.1
unknown
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to invalid logic in the capability check present in the wcal_delete_expired_used_coupon_code function in all versions up to and including 5.16.0. This makes it possible for authenticated attackers with subscriber...
- Affected:
- up to 5.16.1
- Fixed in:
- 5.16.1
- Disclosed:
- Nov 21, 2023
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.16.1
unknown
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wcal_preview_emails function in all versions up to and including 5.16.0. This makes it possible for unauthenticated attackers to preview emails, granted they are able to obt...
- Affected:
- up to 5.16.1
- Fixed in:
- 5.16.1
- Disclosed:
- Nov 21, 2023
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.16.0
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce plugin <= 5.15.2 versions.
- Affected:
- up to 5.16.0
- Fixed in:
- 5.16.0
- Disclosed:
- Oct 16, 2023
CVE-2023-44986 on NVD →
Abandoned Cart Lite for WooCommerce <= 5.15.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.15.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,...
- CVSS:
- 4.4
- Affected:
- up to 5.15.2
- Fixed in:
- 5.16.0
- Disclosed:
- Oct 2, 2023
CVE-2023-44986 on NVD →
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.8.6
unknown
[en] The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.5. This is due to missing or incorrect nonce validation on the wcal_preview_emails() function. This makes it possible for unauthenticated attackers to generate email previe...
- Affected:
- up to 5.8.6
- Fixed in:
- 5.8.6
- Disclosed:
- Jul 12, 2023
CVE-2021-4414 on NVD →
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.2.0
unknown
[en] The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. This makes it possi...
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
- Disclosed:
- Jun 22, 2023
CVE-2019-25152 on NVD →
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.15.0
unknown
[en] The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows unauthenticated attackers to log in a...
- Affected:
- up to 5.15.0
- Fixed in:
- 5.15.0
- Disclosed:
- Jun 8, 2023
CVE-2023-2986 on NVD →
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.8.6
unknown
- Affected:
- up to 5.8.6
- Fixed in:
- 5.8.6
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
critical
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows unauthenticated attackers to log in as use...
- CVSS:
- 9.8
- Affected:
- up to 5.15.1
- Fixed in:
- 5.15.2
- Disclosed:
- Jun 6, 2023
CVE-2023-2986 on NVD →
Abandoned Cart Lite for WooCommerce <= 5.14.1 - Cross-Site Request Forgery via ts_reset_tracking_setting
medium
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.14.1. This is due to missing or incorrect nonce validation on the 'ts_reset_tracking_setting' function. This makes it possible for unauthenticated attackers to reset tracking gran...
- CVSS:
- 4.3
- Affected:
- up to 5.14.2
- Fixed in:
- 5.14.2
- Disclosed:
- May 22, 2023
Abandoned Cart Lite for WooCommerce <= 5.14.1 - Cross-Site Request Forgery via delete_expired_used_coupon_code
medium
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.14.1. This is due to missing or incorrect nonce validation on the 'delete_expired_used_coupon_code' function. This makes it possible for unauthenticated attackers to delete expire...
- CVSS:
- 4.3
- Affected:
- up to 5.14.2
- Fixed in:
- 5.14.2
- Disclosed:
- May 22, 2023
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.14.2
unknown
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.14.1. This is due to missing or incorrect nonce validation on the 'ts_reset_tracking_setting' function. This makes it possible for unauthenticated attackers to reset tracking gran...
- Affected:
- up to 5.14.2
- Fixed in:
- 5.14.2
- Disclosed:
- May 22, 2023
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.14.2
unknown
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.14.1. This is due to missing or incorrect nonce validation on the 'delete_expired_used_coupon_code' function. This makes it possible for unauthenticated attackers to delete expire...
- Affected:
- up to 5.14.2
- Fixed in:
- 5.14.2
- Disclosed:
- May 22, 2023
Abandoned Cart Lite for WooCommerce <= 5.8.5 - Cross-Site Request Forgery Bypass
medium
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.5. This is due to missing or incorrect nonce validation on the wcal_preview_emails() function. This makes it possible for unauthenticated attackers to generate email preview tem...
- CVSS:
- 4.3
- Affected:
- up to 5.8.5
- Fixed in:
- 5.8.6
- Disclosed:
- Mar 1, 2021
CVE-2021-4414 on NVD →
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.8.6
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by NintechNet in WordPress Abandoned Cart Lite for WooCommerce plugin (versions <= 5.8.5).
- Affected:
- up to 5.8.6
- Fixed in:
- 5.8.6
- Disclosed:
- Mar 1, 2021
Abandoned Cart Lite for WooCommerce <= 5.8.2 - SQL Injection
critical
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘billing_first_name' parameter in versions up to, and including, 5.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it poss...
- CVSS:
- 9.8
- Affected:
- up to 5.8.2
- Fixed in:
- 5.8.3
- Disclosed:
- Nov 8, 2020
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.8.3
unknown
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘billing_first_name' parameter in versions up to, and including, 5.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it poss...
- Affected:
- up to 5.8.3
- Fixed in:
- 5.8.3
- Disclosed:
- Nov 8, 2020
Abandoned Cart Lite for WooCommerce < 5.2.0 and Abandoned Cart Pro for WooCommerce < 7.13.0 - Stored Cross-Site Scripting
high
The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. This makes it possible f...
- CVSS:
- 7.2
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
- Disclosed:
- Mar 11, 2019
CVE-2019-25152 on NVD →
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.2.0
unknown
The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. This makes it possible f...
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
- Disclosed:
- Mar 11, 2019
Abandoned Cart Lite for WooCommerce < 1.9 - SQL Injection
high
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ and 'order' parameters in versions up to, and including, 1.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...
- CVSS:
- 8.8
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Jul 15, 2015
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 1.9
unknown
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ and 'order' parameters in versions up to, and including, 1.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Jul 15, 2015
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 1.9
unknown
The Abandoned Cart Lite for WooCommerce WordPress plugin was affected by an Authenticated Blind SQL Injection security vulnerability.
- Affected:
- up to 1.9
- Fixed in:
- 1.9
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.8.3
unknown
The plugin is affected by an unauthenticated SQL injection via the billing_first_name parameter of the save_data AJAX call.
- Affected:
- up to 5.8.3
- Fixed in:
- 5.8.3
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.8.6
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 5.8.6
- Fixed in:
- 5.8.6
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.8.3
unknown
Update the WordPress Abandoned Cart Lite for WooCommerce plugin to the latest available version (at least 5.8.3).
Slavco Mihajloski (mslavco) discovered and reported this SQL Injection vulnerability in WordPress Abandoned Cart Lite for WooCommerce Plugin. This could allow a malicious actor to directly interact with you...
- Affected:
- up to 5.8.3
- Fixed in:
- 5.8.3
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.16.1
unknown
The plugin is vulnerable to unauthorized access of data due to a missing capability check on the wcal_preview_emails function.
This makes it possible for unauthenticated attackers to preview emails, granted they are able to obtain a nonce via a separate vulnerability.
- Affected:
- up to 5.16.1
- Fixed in:
- 5.16.1
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.16.1
unknown
The plugin is vulnerable to unauthorized access of data due to a missing capability check on the wcal_delete_expired_used_coupon_code function.
This makes it possible for unauthenticated attackers to preview emails, granted they are able to obtain a nonce via a separate vulnerability.
- Affected:
- up to 5.16.1
- Fixed in:
- 5.16.1
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 5.16.2
unknown
The plugin does not have CSRF checks in some places, which could allow attackers to make logged in admins perform unwanted actions, such as toggle template statuses via CSRF attacks
- Affected:
- up to 5.16.2
- Fixed in:
- 5.16.2