Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-12585 - Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token

CVE ID :CVE-2026-12585 Published : July 16, 2026, 6 a. m. | 58 minutes ago Description :The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.

8. 2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled. Severity: 0.

Originally reported by CVE Recent
0 comments

0 comments

Posting as BoldOtter953
0/1000

No comments yet. Be the first to start the discussion.