Abandoned Cart Lite for WooCommerce <= 5.16.0 - Improper Authorization via wcal_preview_emails
Strategic Overview
- Status
- Patched in 5.16.1
- Affected Plugin
- Abandoned Cart Lite for WooCommerce
- Affected Version
< 5.16.1- CVSS
- 3.7Low
- Weakness type
- CWE-285 · Improper Authorization
- CVE
CVE pending
At a glance
This record tracks a low-severity Improper Authorization vulnerability in the Abandoned Cart Lite for WooCommerce WordPress plugin, affecting versions < 5.16.1. It carries a CVSS score of 3.7 (reachable over the network). Exploitation requires no authentication. The issue is fixed in version 5.16.1; sites on affected versions should update now. Disclosed November 2023.
Vulnerability Overview
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wcal_preview_emails function in all versions up to and including 5.16.0. This makes it possible for unauthenticated attackers to preview emails, granted they are able to obtain a nonce via a separate vulnerability.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, and no privileges on the target site, and no interaction from a victim user.
CWE-285: Improper Authorization
Reaching this weakness in Abandoned Cart Lite for WooCommerce < 5.16.1 takes a caller who can reach the endpoint. Improper authorization means a permission check exists but does not cover the case being exercised, so a caller who is allowed to do one thing is allowed to do a neighbouring thing as well.
A lower-privileged account performs an action reserved for a higher one, which on a multi-author or membership site means an ordinary user reaching administrative behaviour. For Abandoned Cart Lite for WooCommerce the fix is 5.16.1: builds < 5.16.1 are affected, anything from 5.16.1 onward is not.
Remediation
Update to version 5.16.1, or a newer patched version
How does WordSec protect against this?
Because it turns on account access, WordSec's login security is the relevant layer: role-based two-factor, captcha and brute-force limits raise the cost of getting the account this needs. None of that substitutes for the fix: Abandoned Cart Lite for WooCommerce 5.16.1 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Same weakness class
Other vulnerabilities in Abandoned Cart Lite for WooCommerce
- 9.8CVE-2026-12585: Abandoned Cart Lite… Privilege Escalation
CVE-2026-12585 - 9.8CVE-2023-2986: Abandoned Cart Lite… Authentication Bypass
CVE-2023-2986 - 9.8Abandoned Cart Lite for WooCommerce <= 5.8.2 SQL Injection
- 8.8Abandoned Cart Lite for WooCommerce < 1.9 SQL Injection
- 7.2CVE-2019-25152: Abandoned Cart Lite… and Abandoned Cart Pro
CVE-2019-25152 - 5.4CVE-2023-41671: Abandoned Cart Lite… Missing Authorization
CVE-2023-41671 - 5.3Abandoned Cart Lite for WooCommerce <= 5.16.1 CSRF
- 4.4CVE-2026-65557: Abandoned Cart Lite for WooCommerce Stored XSS
CVE-2026-65557
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C