cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwoocommerce-abandoned-cart woocommerce-abandoned-cart

Direction: ascending
Jun 06, 2024

Abandoned Cart Lite for WooCommerce # d2274f1ff19dbe519f9e6e330360f94e28678f44

Date
Mar 01, 2021
Research Description
Abandoned Cart Lite for WooCommerce [woocommerce-abandoned-cart] < 1.9 (closed) WordPress Abandoned Cart Lite for WooCommerce plugin <= 5.8.5 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability found by NintechNet in WordPress Abandoned Cart Lite for WooCommerce plugin (versions <= 5.8.5).
Affected versions
max 1.9.
Status
vulnerable

Abandoned Cart Lite for WooCommerce # CVE-2021-4414

CVE, Research URL

CVE-2021-4414

Date
Jul 12, 2023
Research Description
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.5. This is due to missing or incorrect nonce validation on the wcal_preview_emails() function. This makes it possible for unauthenticated attackers to generate email preview templates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.9.
Status
vulnerable

Abandoned Cart Lite for WooCommerce # CVE-2023-2986

CVE, Research URL

CVE-2023-2986

Date
Jun 08, 2023
Research Description
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows unauthenticated attackers to log in as users who have abandoned the cart, who are typically customers. Further security hardening was introduced in version 5.15.1 that ensures sites are no longer vulnerable through historical check-out links, and additional hardening was introduced in version 5.15.2 that ensured null key values wouldn't permit the authentication bypass.
Affected versions
max 5.15.0.
Status
vulnerable

Abandoned Cart Lite for WooCommerce # CVE-2021-4342

CVE, Research URL

-

Date
Jun 07, 2023
Research Description
Rejected reason: CVE split into individual CVE IDs for each software record.
Affected versions
max 5.8.6.
Status
vulnerable

Abandoned Cart Lite for WooCommerce # CVE-2019-25152

CVE, Research URL

CVE-2019-25152

Date
Jun 22, 2023
Research Description
The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in user input that will execute on the admin dashboard.
Affected versions
max 5.2.0.
Status
vulnerable

Abandoned Cart Lite for WooCommerce # CVE-2023-44986

CVE, Research URL

CVE-2023-44986

Date
Oct 16, 2023
Research Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce plugin <= 5.15.2 versions.
Affected versions
max 5.16.1.
Status
vulnerable
Jun 10, 2024

Abandoned Cart Lite for WooCommerce # CVE-2023-41671

CVE, Research URL

CVE-2023-41671

Date
Dec 13, 2024
Research Description
Missing Authorization vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Abandoned Cart Lite for WooCommerce: from n/a through 5.16.1.
Affected versions
max 5.16.2.
Status
vulnerable