CVE-2026-14829
Received Received - Intake

Authentication Bypass in Checkimate WordPress Plugin

Vulnerability report for CVE-2026-14829, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The Checkimate β€” WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate β€” WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13's premium licensing state and erase the stored license key.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
checkimate woocommerce_checkout_abandoned_cart_recovery_order_bumps to 1.0.14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-14829 is a vulnerability in the Checkimate WordPress plugin versions 1.0.13 and below. It allows unauthenticated attackers to deactivate the plugin's premium licensing and erase the stored license key by exploiting a hardcoded secret derived from publicly available information. This occurs due to improper access control in the plugin's license-management functionality.

Detection Guidance

Check if the Checkimate WordPress plugin version 1.0.13 or below is installed. Look for unauthorized deactivation of the plugin or erasure of the license key in logs. No specific commands are provided in the context.

Impact Analysis

If you use the affected Checkimate plugin, an attacker could exploit this to disable premium features and remove your license key, potentially disrupting your WooCommerce checkout, abandoned cart recovery, or order bumps functionality. This could lead to loss of paid features and operational disruptions.

Mitigation Strategies

Update the Checkimate WordPress plugin to the latest version beyond 1.0.13 to address the improper access control issue. Monitor for unauthorized changes to the plugin's licensing state.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14829. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart