CyberRota Analysis
AI-GeneratedThe Abandoned Cart Lite for WooCommerce plugin for WordPress versions prior to 6.8.2 is vulnerable due to insufficient protection of cart-recovery tokens, enabling unauthenticated attackers to create forged recovery links that can log them in as other users if automatic login is enabled. This vulnerability poses a significant risk of unauthorized access and potential account compromise. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.