S4E just found a medium ssl lucky13 vulnerability scanner
high·Product Based Web Vulnerabilities·Updated Oct 7, 2025

CVE-2019-25152 Scanner

CVE-2019-25152 Scanner - Cross-Site Scripting (XSS) vulnerability in Abandoned Cart Lite for WooCommerce

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-25152
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in user input that will execute on the admin dashboard.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Abandoned Cart Lite for WooCommerceby tychesoftwares
AFFECTED< 5.2.0SAFE ✓≥ 5.2.0
Abandoned Cart Pro for WooCommerceby TYCHE
0
Updated Aug 21, 2026View on NVD →
Detail

Abandoned Cart Lite for WooCommerce is a WordPress plugin used by e-commerce stores to recover sales from users who abandon their carts. The plugin provides automated reminders to customers, encouraging them to complete their purchases. Developed by Tyche Softwares, it is popular among online retailers for improving sales conversion rates. The plugin integrates seamlessly with WooCommerce, offering an array of customization options for store owners. Users can configure emails, messages, and notifications to be sent to customers based on specific cart abandonment timings. The plugin's analytics feature provides insights on recovered sales, offering valuable data for e-commerce strategies.

The vulnerability in question is a type of Cross-Site Scripting (XSS) attack. This occurs when an attacker injects malicious scripts into web applications, which are then executed in the browser of users who load the page. In the context of the Abandoned Cart Lite for WooCommerce plugin, the vulnerability allows attackers to insert arbitrary scripts into parameters due to improper input sanitization. The injected scripts can be executed within the admin dashboard, potentially compromising the administrator's session. This form of Stored XSS can be particularly damaging because it exploits vulnerabilities that involve storing inputs to be used later. Consequently, such vulnerabilities require prompt attention and remediation.

Technically, the vulnerability arises from the failure to sanitize input data and escape output in the WordPress plugin. Specifically, multiple parameters in the plugin up to version 5.1.3 are affected. The endpoints that handle these parameters fail to perform adequate checks or cleanse the data before processing. This opens the door for attackers to inject JavaScript payloads, which are later rendered on the admin dashboard. As the payload executes, it can perform actions on behalf of the admin, such as cookie theft or redirecting to malicious sites. The vulnerability, if left unpatched, presents a significant security risk for WooCommerce stores.

Exploitation of this vulnerability can lead to several adverse effects. Administrators of WooCommerce stores may have their session hijacked, resulting in unauthorized access. Attackers could gain administrative control, allowing them to alter content, user information, and settings. Sensitive information such as customer details could be exposed or modified. Moreover, once control is established, attackers might distribute malware or launch further attacks on unsuspecting users. The reputational damage to the affected online store could be significant, impacting customer trust and future sales.

REFERENCES

Solution Advice
  • Update the Abandoned Cart Lite for WooCommerce plugin to version 5.2.0 or later.
  • Ensure proper input validation and output escaping throughout your WordPress plugins.
  • Regularly audit plugins for known vulnerabilities and apply patches promptly.
  • Monitor WooCommerce store activity and investigate any suspicious administrative actions.
  • Consider employing Web Application Firewalls (WAF) to help protect against XSS attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-25152 Scanner - Cross-Site Scripting (XSS) vulnerability in Abandoned Cart Lite for WooCommerce S4E