Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Authentication Bypass Using an Alternate Path or Channel flaw that allows attackers to evade normal authentication controls and obtain unauthorized access to the Abandoned Cart Recovery for WooCommerce plugin. This can enable reading or modification of cart recovery data, exposing customer information or altering recovery actions. The weakness corresponds to CWE-288, indicating a failure to enforce proper authentication.

Affected Systems

Any WordPress site that has the VillaTheme Abandoned Cart Recovery for WooCommerce plugin installed at version 1.1.12 or earlier is affected. The issue covers all releases from n/a through <= 1.1.12, so all prior versions are vulnerable until an update is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, via an alternate URL or request path that bypasses authentication checks. Exploitation would require the attacker to discover or guess this alternate path, after which unauthorized access could be achieved.

Generated by OpenCVE AI on July 29, 2026 at 07:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to a version newer than 1.1.12 that includes the authentication fix.
  • If upgrading is not immediately possible, place the site in maintenance mode and restrict WordPress admin access to identified IP addresses or require two‑factor authentication.
  • Disable or remove the Abandoned Cart Recovery for WooCommerce plugin until a patched version is available.

Generated by OpenCVE AI on July 29, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Villatheme
Villatheme abandoned Cart Recovery For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Villatheme
Villatheme abandoned Cart Recovery For Woocommerce
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.
Title WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken Authentication vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Villatheme Abandoned Cart Recovery For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:51:17.490Z

Reserved: 2026-06-25T08:03:56.313Z

Link: CVE-2026-57698

cve-icon Vulnrichment

Updated: 2026-07-13T13:51:14.413Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T08:00:04Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel