← back to popular plugins
wordfence / plugin · woo-cart-abandonment-recovery
Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails
woo-cart-abandonment-recovery
total installs
300,000
total vulns
1
critical
0
high
1
medium
0
low
0
latest vuln
—
patched
1
unpatched
0
avg time to patch
—
vulnerabilities
(1)
Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails < 2.1.0 - Authenticated (Shop Manager+) Privilege Escalation
high
✓ patched
cve id
CVE-2026-39470 ↗
cvss score
7.2
cwe
CWE-266: Incorrect Privilege Assignment
published
Apr 8, 2026
The Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.1.0 (exclusive). This makes it possible for authenticated attackers, with Shop Manager-level access and above, to escalate their privileges to that of an administrator.