Loading HuntDB...

GHSA-54x7-q6m6-mjqv

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows unauthenticated attackers to log in as users who have abandoned the cart, which users are typically customers.

Related CVEs

Key Information

GHSA ID
GHSA-54x7-q6m6-mjqv
Published
June 8, 2023 3:30 AM
Last Modified
April 4, 2024 4:40 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.