LetsRecover – WooCommerce Abandoned Cart Notifications
LetsRecover – WooCommerce Abandoned Cart Notifications has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2022; all 3 are fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 2 high. 2022 was the busiest year with 3 disclosures.
The most common weakness is SQL Injection, behind 3 of the records (100%).
Every one of the 3 issues recorded for LetsRecover – WooCommerce Abandoned Cart Notifications has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Kunal Sharma. The current release is tested up to WordPress 6.1.12.
CVE-2022-4357LetsRecover <= 1.1.0 - Unauthenticated SQL Injection via AJAX action
Read the full analysisVulnerability Records

LetsRecover – WooCommerce Abandoned Cart Notifications
Author
Tahir Jamil
LetsRecover WooCommerce Abandoned Cart Notification is a WordPress plugin for WooCommerce that is used for abandoned carts recovery using Web Push Notifications and increase the sales. When a user clicks “Add to Cart” for the first time, an opt-in prompt is displayed to ask the permission for notifications. If user grants notification permission the plugin capture the cart immediately as an Abandoned Cart along with user’s subscription information. Later the plugin sends automated recovery reminder as a web push notification to user at a predefined interval and template. Features One-click User Subscription Automated Recovery Reminder Works for Both Members and Guests Customizable Templates Individual Notification Report Individual Template Report Subscriber’s Report Abandoned Cart Detail Notification Status Delivery Status Click status Close Status
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C