Impact
The Abandoned Cart Lite for WooCommerce plugin creates cart‑recovery tokens that are neither signed nor bound to a specific user account. As a result, an attacker can generate a token that mimics a legitimate recovery link. When the plugin’s automatic‑login feature is turned on, visiting such a link logs the user in as the account to which the token claims to belong, giving the attacker full access to that account’s data and administrative privileges. The flaw is an authentication bypass weakness (CWE‑287).
Affected Systems
WordPress sites that have installed Abandoned Cart Lite for WooCommerce version 6.8.1 or earlier are affected. These sites must have the plugin’s automatic‑login option enabled for the exploit to be successful.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, reflecting its high severity. The EPSS score is below 1%, indicating a very low yet non‑zero likelihood of exploitation in the general population. It is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated, as the attacker need only supply a forged recovery link to an end user. Based on the description, we infer that the attacker can deliver the forged link through email, messaging, or other channels, though this method is not explicitly documented.
OpenCVE Enrichment