CSRF
5 records33.3%First: 2021. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 15 vulnerability records associated with Abandoned Cart Lite for WooCommerce, published between 2015 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2015 | 1 | |
| 2019 | 1 | |
| 2020 | 1 | |
| 2021 | 1 | |
| 2023 | 8 | |
| 2026 | 3 |
| Severity | Records | Share |
|---|---|---|
| Critical | 3 | 20% |
| High | 2 | 13.3% |
| Medium | 8 | 53.3% |
| Low | 2 | 13.3% |
First: 2021. Latest: 2026.
First: 2019. Latest: 2026.
First: 2023. Latest: 2023.
First: 2015. Latest: 2020.
First: 2023. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.8.16.8.25.16.25.16.15.16.05.15.25.14.25.8.65.8.35.2.01.9Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-6.8.0 | Abandoned Cart Lite for WooCommerce <= 6.8.0 - Authenticated (Shop manager+) Stored Cross-Site Scripting | July 24, 2026 | 6.8.1 | Medium |
*-6.8.0 | Abandoned Cart Lite for WooCommerce <= 6.8.0 - Cross-Site Request Forgery | June 26, 2026 | 6.8.1 | Medium |
*-6.8.1 | Abandoned Cart Lite for WooCommerce <= 6.8.1 - Unauthenticated Privilege Escalation via Weak Recovery Link | June 25, 2026 | 6.8.2 | Critical |
*-5.16.1 | Abandoned Cart Lite for WooCommerce <= 5.16.1 - Cross-Site Request Forgery | December 1, 2023 | 5.16.2 | Medium |
*-5.16.1 | Abandoned Cart Lite for WooCommerce <= 5.16.1 - Missing Authorization via multiple AJAX functions | November 28, 2023 | 5.16.2 | Medium |
[*, 5.16.1) | Abandoned Cart Lite for WooCommerce <= 5.16.0 - Improper Authorization via wcal_delete_expired_used_coupon_code | November 21, 2023 | 5.16.1 | Low |
[*, 5.16.1) | Abandoned Cart Lite for WooCommerce <= 5.16.0 - Improper Authorization via wcal_preview_emails | November 21, 2023 | 5.16.1 | Low |
*-5.15.2 | Abandoned Cart Lite for WooCommerce <= 5.15.2 - Authenticated (Administrator+) Stored Cross-Site Scripting | October 2, 2023 | 5.16.0 | Medium |
*-5.15.1 | Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass | June 6, 2023 | 5.15.2 | Critical |
[*, 5.14.2) | Abandoned Cart Lite for WooCommerce <= 5.14.1 - Cross-Site Request Forgery via ts_reset_tracking_setting | May 22, 2023 | 5.14.2 | Medium |
[*, 5.14.2) | Abandoned Cart Lite for WooCommerce <= 5.14.1 - Cross-Site Request Forgery via delete_expired_used_coupon_code | May 22, 2023 | 5.14.2 | Medium |
*-5.8.5 | Abandoned Cart Lite for WooCommerce <= 5.8.5 - Cross-Site Request Forgery Bypass | March 1, 2021 | 5.8.6 | Medium |
*-5.8.2 | Abandoned Cart Lite for WooCommerce <= 5.8.2 - SQL Injection | November 8, 2020 | 5.8.3 | Critical |
[*, 5.2.0) | Abandoned Cart Lite for WooCommerce < 5.2.0 and Abandoned Cart Pro for WooCommerce < 7.13.0 - Stored Cross-Site Scripting | March 11, 2019 | 5.2.0 | High |
[*, 1.9) | Abandoned Cart Lite for WooCommerce < 1.9 - SQL Injection | July 15, 2015 | 1.9 | High |
Selected source records
Published: July 24, 2026
Published: June 26, 2026
Published: June 25, 2026
Published: December 1, 2023
Published: November 28, 2023
Published: November 21, 2023
Published: November 21, 2023
Published: October 2, 2023
Published: November 8, 2020
Published: June 6, 2023
Published: June 25, 2026
Published: July 15, 2015
Published: March 11, 2019
Published: November 28, 2023
Published: December 1, 2023
Published: July 24, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.