Impact
The vulnerability is an Authentication Bypass Using an Alternate Path or Channel flaw that allows attackers to evade normal authentication controls and obtain unauthorized access to the Abandoned Cart Recovery for WooCommerce plugin. This can enable reading or modification of cart recovery data, exposing customer information or altering recovery actions. The weakness corresponds to CWE-288, indicating a failure to enforce proper authentication.
Affected Systems
Any WordPress site that has the VillaTheme Abandoned Cart Recovery for WooCommerce plugin installed at version 1.1.12 or earlier is affected. The issue covers all releases from n/a through <= 1.1.12, so all prior versions are vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, via an alternate URL or request path that bypasses authentication checks. Exploitation would require the attacker to discover or guess this alternate path, after which unauthorized access could be achieved.
OpenCVE Enrichment