Impact
The vulnerability is an Authentication Bypass Using an Alternate Path or Channel flaw that permits attackers to bypass normal authentication controls to obtain unauthorized access to the Abandoned Cart Recovery for WooCommerce plugin. The weakness corresponds to CWE‑288, indicating a failure to enforce proper authentication. The CVE description does not specify the exact impact beyond unauthorized authentication, so the specific consequences (such as data exposure or privilege escalation) are not detailed in the provided information.
Affected Systems
Any WordPress site that has the VillaTheme Abandoned Cart Recovery for WooCommerce plugin installed at version 1.1.12 or earlier is affected. The issue covers all releases from n/a through <= 1.1.12, so all prior versions are vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV. The description states an authentication bypass via an alternate path or channel, but the exact attack vector is not described; it is inferred that an attacker could craft or guess an alternate URL or endpoint that bypasses authentication checks. Without further detail, the likelihood of successful exploitation depends on an attacker identifying such a path. The impact is limited to unauthorized access to the plugin’s functionalities, which could potentially expose or manipulate cart recovery data, but these risks are not expressly documented in the CVE.
OpenCVE Enrichment