PT-2026-68395 · WordPress · Checkmate
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin versions prior to 1.0.14
Description
Insufficient access restrictions in the license-management functionality allow unauthenticated attackers to deactivate the premium licensing state and erase the stored license key. This occurs because the plugin relies on a shared secret computed entirely from publicly available information.
Recommendations
Update the plugin to version 1.0.14 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmate