WooCommerce Recover Abandoned Cart PHP Object Injection Vulnerability

Vulnerability

A PHP Object Injection vulnerability has been identified in the WooCommerce Recover Abandoned Cart plugin for WordPress, affecting all versions through 24.4.0. The vulnerability arises from the deserialization of untrusted data from the 'raccookie_guest_email' cookie, allowing unauthenticated attackers to inject PHP objects. While the vulnerable plugin itself does not have a known payload execution chain, the vulnerability could be exploited if another plugin or theme with a compatible chain is installed, potentially leading to unauthorized file deletion, sensitive data exposure, or arbitrary code execution.

Impact

Exploitation of this vulnerability could allow for PHP Object Injection, with the possibility of executing actions such as deleting files, accessing sensitive information, or executing code, but only if an additional plugin or theme that facilitates such exploitation is present on the site.

Remediation

Users are advised to update the WooCommerce Recover Abandoned Cart plugin to version 24.5.0 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.