A Cross Site Scripting (XSS) vulnerability was found in the Abandoned Cart Lite for WooCommerce plugin, affecting versions up to 6.8.0. This issue allows an attacker to inject malicious scripts into web pages viewed by other users. The vulnerability requires high privileges (PR:H) and user interaction (UI:R) to exploit, with a scope of C (S:C), and can result in low impact to confidentiality (C:L), integr [truncated]
CVE-2026-56048 is a medium-severity vulnerability in Payment Gateway Based Fees and Discounts for WooCommerce plugin versions <= 3.0.0. This Unauthenticated Insecure Direct Object References (IDOR) vulnerability, with a CVSS score of 6.5, allows attackers to manipulate objects without proper authorization. The vulnerability was published on June 26, 2026, and last modified on June 29, 2026. Evidence from [truncated]
CVE-2026-42386 is a critical unauthenticated SQL injection vulnerability in the Order Delivery Date for WooCommerce plugin. The vulnerability has a CVSS score of 9.3 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-42386). The affected plugin versions are <= 4.5.1.