Executive brief
Abandoned Cart Lite for WooCommerce, a WordPress plugin used to recover lost sales by tracking unfinished checkouts, is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By persuading a logged-in site manager to click a malicious link, an attacker could potentially modify plugin settings or data without authorization. This could disrupt store operations or lead to unauthorized changes in how the store handles abandoned customer carts.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Abandoned Cart Lite for WooCommerce plugin for WordPress due to insufficient nonce validation on sensitive actions. The flaw affects versions up to and including 6.8.0. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a site administrator into executing it while authenticated (e.g., via social engineering or a malicious link). Successful exploitation allows the attacker to perform actions on behalf of the administrator, such as modifying plugin configurations. The issue is resolved in version 6.8.1.
Affected products
- Tyche Softwares Abandoned Cart Lite for WooCommerce <= 6.8.0
Timeline
- 2026-06-09: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-06-26: advisory: Public advisory published by Patchstack and NVD
- 2026-06-26: patched: Version 6.8.1 released to address the vulnerability