CVE-2026-12585
Deferred Deferred - Pending Action

Abandoned Cart Lite for WooCommerce Session Hijacking

Vulnerability report for CVE-2026-12585, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-16

Last updated on: 2026-07-16

Assigner: WPScan

Description

The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-16
Last Modified
2026-07-16
Generated
2026-08-05
AI Q&A
2026-07-16
EPSS Evaluated
2026-08-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
woocommerce abandoned_cart_lite to 6.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Abandoned Cart Lite for WooCommerce plugin before version 6.8.2. It allows unauthenticated attackers to forge cart-recovery tokens that are not bound to specific accounts. When the automatic-login feature is enabled, attackers can use these forged tokens to log in as any user without authentication.

Detection Guidance

To detect this vulnerability, check the version of the Abandoned Cart Lite for WooCommerce plugin. If it is below 6.8.2, the system is vulnerable. Use commands like 'wp plugin list' in WordPress or inspect the plugin directory for version details.

Impact Analysis

This vulnerability can lead to unauthorized account access for users of the affected plugin. Attackers could take over user accounts, potentially accessing sensitive data like personal information or order details. It poses a risk to user privacy and could enable further malicious activities within the compromised accounts.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to personal and sensitive data. GDPR requires protecting personal data, and HIPAA mandates safeguarding health information. A breach via this vulnerability may result in legal penalties and loss of trust.

Mitigation Strategies

Immediately update the Abandoned Cart Lite for WooCommerce plugin to version 6.8.2 or later. Disable the automatic-login feature in the plugin settings if possible. Monitor user accounts for unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12585. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart