WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Abandoned Cart Lite for WooCommerce

Track abandoned carts and send automated, customizable abandoned cart recovery emails. Reduce cart abandonment, recover lost revenue & increase sales.

14Reported vulnerabilities
9.8Highest CVSS score
6.8.3Latest version
20,000+Active installs

What to do now

Update Abandoned Cart Lite for WooCommerce to 6.8.1 or later. 14 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 29, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-2986 Critical 9.8 42.5% 5.14.2 and earlier 5.15.2 June 8, 2023
CVE-2026-12585 Critical 9.8 0.4% 6.8.1 and earlier 6.8.2 June 25, 2026
WF-562d0052-7f1a-441b-9ff7-1c8bcb4b74b4 Critical 9.8 5.8.2 and earlier 5.8.3 November 8, 2020
WF-00243844-a2ec-42fd-84d9-03e89619e361 High 8.8 Before 1.9 1.9 July 15, 2015
CVE-2023-41671 Medium 5.4 0.5% 5.16.1 and earlier 5.16.2 November 28, 2023
WF-1ce1316b-674a-4436-968f-9ffca4e8f726 Medium 5.3 5.16.1 and earlier 5.16.2 December 1, 2023
CVE-2023-44986 Medium 4.4 0.3% 5.15.2 and earlier 5.16.0 October 2, 2023
CVE-2026-65557 Medium 4.4 0.1% 6.8.0 and earlier 6.8.1 July 24, 2026
CVE-2026-57637 Medium 4.3 0.1% 6.8.0 and earlier 6.8.1 June 26, 2026
CVE-2021-4414 Medium 4.3 0.4% 5.8.5 and earlier 5.8.6 July 12, 2023
WF-a1e51a99-f5d4-47d4-bead-00ca1f5f72c2 Medium 4.3 Before 5.14.2 5.14.2 May 22, 2023
WF-e743e656-2dd9-43ed-a190-b03af7c75c54 Medium 4.3 Before 5.14.2 5.14.2 May 22, 2023
WF-4edbfeee-b668-4a85-a030-c15d6583dc82 Low 3.7 Before 5.16.1 5.16.1 November 21, 2023
WF-52d1f9a3-243e-4e2c-a752-f40b6d275121 Low 3.1 Before 5.16.1 5.16.1 November 21, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.