Junglewise Threat Intelligence

CVE-2026-57698: VillaTheme Abandoned Cart Recovery for WooCommerce authentication bypass

CVE-2026-57698 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Vendors: VillaTheme.

Executive brief

A security vulnerability exists in the Abandoned Cart Recovery for WooCommerce plugin, which is used by online stores to re-engage customers who leave items in their shopping carts. An attacker can bypass security checks to perform actions that should be restricted to authorized users, potentially leading to unauthorized administrative access to the website. This could result in the theft of customer data, site defacement, or a complete takeover of the online store.

Technical details

An Authentication Bypass Using an Alternate Path or Channel (CWE-288) vulnerability exists in the VillaTheme Abandoned Cart Recovery for WooCommerce plugin through version 1.1.12. The flaw allows an unauthenticated remote attacker to bypass authentication mechanisms by accessing specific endpoints or channels that do not properly enforce authorization checks. Successful exploitation could allow an attacker to perform actions typically reserved for high-privileged users, including potential administrative account takeover. The issue is resolved in version 1.1.13.

Affected products

  • VillaTheme Abandoned Cart Recovery for WooCommerce <= 1.1.12

Timeline

  • 2026-05-30: disclosed: Reported by she11f to Patchstack
  • 2026-07-08: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE record
  • 2026-07-13: patched: Version 1.1.13 released to address the vulnerability

References