Junglewise Threat Intelligence

CVE-2026-65557: Tychesoftwares Abandoned Cart Lite for WooCommerce XSS

CVE-2026-65557 · Severity: medium · CVSS 5.9 · Published 2026-07-27

Technologies: Tyche Softwares Abandoned Cart Lite for WooCommerce. Vendors: Tyche Softwares.

Executive brief

Abandoned Cart Lite for WooCommerce is a WordPress plugin used by online stores to recover lost sales by tracking and emailing customers who leave items in their shopping carts. A security vulnerability in versions 6.8.0 and earlier allows a user with 'Shop Manager' privileges to inject malicious scripts into the website. If an administrator or another user views the affected area, these scripts could be used to redirect visitors to malicious sites, display unauthorized advertisements, or perform actions on behalf of the victim.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Abandoned Cart Lite for WooCommerce plugin for WordPress (versions <= 6.8.0). The flaw is due to improper neutralization of input during web page generation (CWE-79). An attacker with 'Shop Manager' or higher privileges can inject malicious HTML or JavaScript payloads that execute in the context of a victim's browser, typically requiring a more privileged user (like an Administrator) to interact with a specific page or link. This is classified as a stored XSS vulnerability with a CVSS 3.1 base score of 5.9. The issue is resolved in version 6.8.1.

Affected products

  • Tychesoftwares Abandoned Cart Lite for WooCommerce <= 6.8.0

Timeline

  • 2026-06-09: other: Reported by researcher Ananda Dhakal via Patchstack
  • 2026-07-24: advisory: Patchstack advisory published
  • 2026-07-27: disclosed: CVE published to NVD dataset
  • 2026-07-27: patched: Version 6.8.1 released to address the vulnerability

References

Related threats