What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce plugin <= 5.15.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce plugin <= 5.15.2 versions.
Explanation of Vulnerability in Simple Terms
Abandoned Cart Lite for WooCommerce versions up to 5.15.2 contain a stored cross-site scripting (XSS) vulnerability. An authenticated admin user with high privileges can inject malicious scripts through the plugin's interface. When other users view affected pages, the injected code executes in their browsers, potentially compromising their sessions or stealing data. Update to a version newer than 5.15.2.
What an attacker can do
Inject malicious scripts that execute in other users' browsers when they view affected pages.
Potential impact on your site
Admin accounts can be compromised; customer data and sessions at risk if malicious scripts are injected via the plugin.
Conditions required to exploit
Attacker must have admin-level access to the WordPress site and a victim must view a page containing the injected payload.
Key dates
External resources
Related vulnerabilities