Impact
The vulnerability is a classic cross‑site scripting flaw in the Abandoned Cart Lite for WooCommerce plugin (versions 6.8.0 and earlier). Arbitrary JavaScript code can be injected and executed in a victim’s browser while using the affected site, potentially enabling session hijacking, data theft, or defacement. The weakness is indexed as CWE‑79 and is rated by the CVSS system as a moderate‑severity issue (5.9).
Affected Systems
The plugin is distributed by Tychesoftwares and can be installed on any WordPress site using the plugin. All instances of the plugin up to and including version 6.8.0 are affected, while version 6.8.1 and later contain the fix.
Risk and Exploitability
The EPSS score of 0.0014 indicates a low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation yet. Based on the nature of the flaw, the most probable attack vector involves interaction with the shop manager section of the plugin where user‑supplied data is rendered without adequate sanitization. Users or administrators can trigger the vulnerability by entering crafted input that is subsequently reflected in the web interface. Given the moderate CVSS score, the risk is considered significant enough to warrant prompt remediation.
OpenCVE Enrichment