Authentication Bypass in VillaTheme Abandoned Cart Recovery for WooCommerce
CVE-2026-57698
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 July 2026
What is CVE-2026-57698?
An authentication bypass vulnerability exists in the VillaTheme Abandoned Cart Recovery for WooCommerce plugin, allowing unauthorized access through alternative methods. This poses significant risks as it enables attackers to exploit authentication flaws and manipulate sensitive operations, particularly affecting WooCommerce stores running versions up to 1.1.12. Immediate updates and security measures are strongly recommended to safeguard against potential abuse and maintain system integrity.
Affected Version(s)
Abandoned Cart Recovery for WooCommerce 0 <= 1.1.12