Impact
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through version 1.0.13 fails to enforce authentication for its license‑management API. The API relies on a shared secret computed entirely from publicly available data, so an attacker who can reach the endpoint can send a request that removes the stored license key. This operation deactivates the premium licensing state, potentially causing the plugin to downgrade or stop functioning. The vulnerability does not provide privilege escalation beyond the loss of licensing, nor does it expose other data or allow code execution.
Affected Systems
Any WordPress site running the Checkimate plugin, vendor unknown, using version 1.0.13 or earlier. The vulnerability affects the entire plugin installation, regardless of user roles or site configuration.
Risk and Exploitability
The CVSS score is not provided, but the ability to remove a license key is a clear denial‑of‑service or feature‑deactivation flaw. The EPSS score is unavailable and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation. Attackers could likely trigger the flaw by sending an unauthenticated HTTP request to the license‑management endpoint, as the required secret can be constructed from public information. The risk is that any compromised or attacked site could lose premium functionality without owner intervention.
OpenCVE Enrichment