CVE-2021-4414: Abandoned Cart Lite for WooCommerce <= 5.8.5 - Cross-Site Request Forgery Bypass
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.5. This is due to missing or incorrect nonce validation on the wcalpreviewemails() function. This makes it possible for unauthenticated attackers to generate email preview templates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-4414?
CVE-2021-4414 is a vulnerability in the Abandoned Cart Lite for WooCommerce plugin for WordPress that allows for Cross-Site Request Forgery.
How severe is CVE-2021-4414?
CVE-2021-4414 has a severity level of medium.
What software versions are affected by CVE-2021-4414?
Versions up to and including 5.8.5 of the Abandoned Cart Lite for WooCommerce plugin for WordPress are affected by CVE-2021-4414.
How can I fix CVE-2021-4414?
To fix CVE-2021-4414, update the Abandoned Cart Lite for WooCommerce plugin for WordPress to a version higher than 5.8.5.
Where can I find more information about CVE-2021-4414?
You can find more information about CVE-2021-4414 on the Wordfence and WordPress plugins websites.