CVE ID :CVE-2026-12585 Published : July 16, 2026, 6 a. m. | 58 minutes ago Description :The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.
8. 2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled. Severity: 0.
0 comments
No comments yet. Be the first to start the discussion.