Impact
A Cross‑Site Request Forgery flaw in Recapture for WooCommerce allows an attacker to alter the plugin’s settings by submitting a forged HTTP request. The vulnerability can be leveraged to change various configuration options exposed by the plugin, potentially affecting how abandoned carts are recovered.
Affected Systems
WordPress sites running the Recapture Cart Recovery and Email Marketing plugin, Recapture for WooCommerce, with versions up to and including 1.0.43.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog. The likely attack vector is a CSRF attack that requires the submission of a forged request to the plugin’s settings endpoint; the attacker typically needs a victim who is authenticated to the site’s administration area. No additional conditions are documented in the CVE data beyond a standard CSRF attack.
OpenCVE Enrichment
EUVD