Description
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13's premium licensing state and erase the stored license key.
Published: 2026-08-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through version 1.0.13 fails to enforce authentication for its license‑management API. The API relies on a shared secret computed entirely from publicly available data, so an attacker who can reach the endpoint can send a request that removes the stored license key. This operation deactivates the premium licensing state, potentially causing the plugin to downgrade or stop functioning. The vulnerability does not provide privilege escalation beyond the loss of licensing, nor does it expose other data or allow code execution.

Affected Systems

Any WordPress site running the Checkimate plugin, vendor unknown, using version 1.0.13 or earlier. The vulnerability affects the entire plugin installation, regardless of user roles or site configuration.

Risk and Exploitability

The CVSS score is not provided, but the ability to remove a license key is a clear denial‑of‑service or feature‑deactivation flaw. The EPSS score is unavailable and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation. Attackers could likely trigger the flaw by sending an unauthenticated HTTP request to the license‑management endpoint, as the required secret can be constructed from public information. The risk is that any compromised or attacked site could lose premium functionality without owner intervention.

Generated by OpenCVE AI on August 6, 2026 at 07:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Checkimate plugin to the latest available version that fixes the license‑deactivation flaw
  • If an upgrade is not yet available, disable or remove the plugin to eliminate the vulnerable functionality
  • Implement a web application firewall rule to block unauthenticated access to the license‑management endpoint, blocking the known request pattern

Generated by OpenCVE AI on August 6, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 06 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13's premium licensing state and erase the stored license key.
Title Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-06T06:00:11.378Z

Reserved: 2026-07-06T09:08:34.459Z

Link: CVE-2026-14829

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T07:30:16Z

Weaknesses