Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
Vulnerability Description
The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Abandoned Cart Lite for WooCommerce 授权问题漏洞
Vulnerability Description
WordPress Abandoned Cart Lite for WooCommerce是WordPress基金会的一款WooCommerce购物车恢复插件。 WordPress Abandoned Cart Lite for WooCommerce 6.8.2之前版本存在授权问题漏洞,该漏洞源于未保护购物车恢复令牌的完整性或将其绑定到请求账户,可能导致未经验证的攻击者伪造恢复链接,在启用自动登录选项时以其他用户身份登录。
CVSS Information
N/A
Vulnerability Type
N/A