← WordPress Vulnerabilities
WordPress security by component

WooCommerce Cart Abandonment Recovery

WooCommerce Cart Abandonment Recovery is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 7.2.

Plugin slug: woo-cart-abandonment-recovery

CVE-2026-39470: WooCommerce Cart Abandonment Recovery: Privilege escalation or authentication bypass

WooCommerce Cart Abandonment Recovery is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a to < 2.1.0.

PublishedJun 15, 2026
Known safe version2.1.0
Safe version
Jun 15, 2026 CVE-2026-39470
WooCommerce Cart Abandonment Recovery: Privilege escalation or authentication bypass
WooCommerce Cart Abandonment Recovery is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a to < 2.1.0.
2.1.0
CVE7.2
NVDPending