Description
The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.
Published: 2026-07-16
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Abandoned Cart Lite for WooCommerce plugin creates cart‑recovery tokens that are neither signed nor bound to a specific user account. As a result, an attacker can generate a token that mimics a legitimate recovery link. When the plugin’s automatic‑login feature is turned on, visiting such a link logs the user in as the account to which the token claims to belong, giving the attacker full access to that account’s data and administrative privileges. The flaw is an authentication bypass weakness (CWE‑287).

Affected Systems

WordPress sites that have installed Abandoned Cart Lite for WooCommerce version 6.8.1 or earlier are affected. These sites must have the plugin’s automatic‑login option enabled for the exploit to be successful.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1, reflecting its high severity. The EPSS score is below 1%, indicating a very low yet non‑zero likelihood of exploitation in the general population. It is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated, as the attacker need only supply a forged recovery link to an end user. Based on the description, we infer that the attacker can deliver the forged link through email, messaging, or other channels, though this method is not explicitly documented.

Generated by OpenCVE AI on August 1, 2026 at 08:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Abandoned Cart Lite for WooCommerce to version 6.8.2 or newer, which implements token integrity checks and user binding.
  • If an upgrade is not immediately possible, disable the plugin’s automatic‑login feature to prevent forged links from logging users in automatically.
  • Monitor authentication logs for logins that originate from cart‑recovery URLs and block any IP addresses that trigger abnormal login patterns.

Generated by OpenCVE AI on August 1, 2026 at 08:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.
Title Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-16T16:57:01.246Z

Reserved: 2026-06-18T07:06:18.053Z

Link: CVE-2026-12585

cve-icon Vulnrichment

Updated: 2026-07-16T16:56:46.176Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:00:04Z

Weaknesses