Known vulnerabilities in Abandoned Cart Recovery for WooCommerce
A simple, effective solution to capture abandoned carts and auto-send reminders. Track logs and generate reports on carts, emails, and more
2Reported vulnerabilities
7.2Highest CVSS score
1.1.14Latest version
3,000+Active installs
What to do now
Update Abandoned Cart Recovery for WooCommerce to 1.1.13 or later.
2 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-32526 | High | 0.2% | 1.1.10 and earlier | 1.1.11 |
March 20, 2026 |
| CVE-2026-57698 | Medium | 0.4% | 1.1.12 and earlier | 1.1.13 |
July 8, 2026 |