Description
Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abandoned-cart allows Cross Site Request Forgery.This issue affects Recover abandoned cart for WooCommerce: from n/a through <= 2.2.
Published: 2025-04-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic Cross‑Site Request Forgery flaw (CWE‑352) in the Recover abandoned cart for WooCommerce plugin, allowing an attacker to forge requests that are executed with the privileges of an authenticated user. The flaw does not grant remote code execution but can be used to manipulate cart or order data, potentially leading to financial loss or data tampering. The CVSS score of 4.3 reflects a moderate impact but limited scope. Based on the description, the typical CSRF injection requires an attacker to host a malicious page that lures the victim, while the victim is logged into the site, to automatically submit a forged request to the plugin’s endpoint.

Affected Systems

The affected product is the Recover abandoned cart for WooCommerce plugin by sonalsinha21, versions up to and including 2.2. This WordPress plugin is commonly installed on e‑commerce sites that rely on WooCommerce to handle abandoned cart functionality.

Risk and Exploitability

The likely attack vector is inferred from standard CSRF mechanics; an attacker would need a user authenticated to the target site and must trick them into visiting a malicious page that automatically submits a forged request to the plugin’s endpoint. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The risk level is moderate due to the need for user authentication and the potential impact on e‑commerce operations.

Generated by OpenCVE AI on May 1, 2026 at 09:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Recover abandoned cart for WooCommerce plugin to a version newer than 2.2.
  • If a newer release is not yet available, disable the plugin to eliminate the CSRF surface area while a fix is released.
  • Implement additional CSRF token validation for all state‑changing requests in the plugin, in line with CWE‑352 mitigation practices.

Generated by OpenCVE AI on May 1, 2026 at 09:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12317 Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce allows Cross Site Request Forgery. This issue affects Recover abandoned cart for WooCommerce: from n/a through 2.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce allows Cross Site Request Forgery. This issue affects Recover abandoned cart for WooCommerce: from n/a through 2.2. Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abandoned-cart allows Cross Site Request Forgery.This issue affects Recover abandoned cart for WooCommerce: from n/a through <= 2.2.
Title WordPress Recover abandoned cart for WooCommerce <= 2.2 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Recover abandoned cart for WooCommerce plugin <= 2.2 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 29 Apr 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Sktthemes
Sktthemes recover Abandoned Cart For Woocommerce
CPEs cpe:2.3:a:sktthemes:recover_abandoned_cart_for_woocommerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Sktthemes
Sktthemes recover Abandoned Cart For Woocommerce

Tue, 22 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Apr 2025 10:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce allows Cross Site Request Forgery. This issue affects Recover abandoned cart for WooCommerce: from n/a through 2.2.
Title WordPress Recover abandoned cart for WooCommerce <= 2.2 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Sktthemes Recover Abandoned Cart For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:36.892Z

Reserved: 2025-04-22T09:21:32.319Z

Link: CVE-2025-46243

cve-icon Vulnrichment

Updated: 2025-04-22T16:47:47.955Z

cve-icon NVD

Status : Modified

Published: 2025-04-22T10:15:18.390

Modified: 2026-04-23T15:29:56.437

Link: CVE-2025-46243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T09:30:14Z

Weaknesses