Extension WordPress
Vulnérabilités Abandoned Cart Lite for WooCommerce
Cette page rassemble les failles publiées pour Abandoned Cart Lite for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Abandoned Cart Lite for WooCommerce
13 fiches
Abandoned Cart Lite for WooCommerce <= 6.8.0 – Cross-Site Request Forgery
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.8.0. This is due to missing or incorrect nonce validation on a function. This makes it possible…
*-6.8.0
6.8.1
26/06/2026
Abandoned Cart Lite for WooCommerce <= 5.16.1 – Cross-Site Request Forgery
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.16.1. This is due to missing or incorrect nonce validation on the functions corresponding to AJAX…
*-5.16.1
5.16.2
01/12/2023
Abandoned Cart Lite for WooCommerce <= 5.16.1 – Missing Authorization via multiple AJAX functions
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to missing capability checks on multiple AJAX functions in versions up to, and including, 5.16.1. This makes…
*-5.16.1
5.16.2
28/11/2023
Abandoned Cart Lite for WooCommerce <= 5.16.0 – Improper Authorization via wcal_delete_expired_used_coupon_code
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to invalid logic in the capability check present in the wcal_delete_expired_used_coupon_code function in all versions up to and including 5.16.0. This…
[*, 5.16.1)
5.16.1
21/11/2023
Abandoned Cart Lite for WooCommerce <= 5.16.0 – Improper Authorization via wcal_preview_emails
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wcal_preview_emails function in all versions up to and including 5.16.0. This makes it possible…
[*, 5.16.1)
5.16.1
21/11/2023
Abandoned Cart Lite for WooCommerce <= 5.15.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.15.2 due to insufficient input sanitization and output escaping. This makes it possible for…
*-5.15.2
5.16.0
02/10/2023
Abandoned Cart Lite for WooCommerce <= 5.15.1 – Authentication Bypass
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode…
*-5.15.1
5.15.2
06/06/2023
Abandoned Cart Lite for WooCommerce <= 5.14.1 – Cross-Site Request Forgery via ts_reset_tracking_setting
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.14.1. This is due to missing or incorrect nonce validation on the 'ts_reset_tracking_setting' function. This makes it…
[*, 5.14.2)
5.14.2
22/05/2023
Abandoned Cart Lite for WooCommerce <= 5.14.1 – Cross-Site Request Forgery via delete_expired_used_coupon_code
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.14.1. This is due to missing or incorrect nonce validation on the 'delete_expired_used_coupon_code' function. This makes it…
[*, 5.14.2)
5.14.2
22/05/2023
Abandoned Cart Lite for WooCommerce <= 5.8.5 – Cross-Site Request Forgery Bypass
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.5. This is due to missing or incorrect nonce validation on the wcal_preview_emails() function. This makes it…
*-5.8.5
5.8.6
01/03/2021
Abandoned Cart Lite for WooCommerce <= 5.8.2 – SQL Injection
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ‘billing_first_name' parameter in versions up to, and including, 5.8.2 due to insufficient escaping on the user supplied parameter and lack of…
*-5.8.2
5.8.3
08/11/2020
Abandoned Cart Lite for WooCommerce < 5.2.0 and Abandoned Cart Pro for WooCommerce < 7.13.0 – Stored Cross-Site Scripting
The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input…
[*, 5.2.0)
5.2.0
11/03/2019
Abandoned Cart Lite for WooCommerce < 1.9 – SQL Injection
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ and 'order' parameters in versions up to, and including, 1.8 due to insufficient escaping on the user supplied parameter and…
[*, 1.9)
1.9
15/07/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.