Input validation vulnerability in LetsRecover – WooCommerce Abandoned Cart Notifications 1.1.0

The LetsRecover plugin for WordPress has a security vulnerability that affects versions up to and including 1.1.0. An attacker with administrator privileges can inject additional SQL queries into existing queries that can be used to get access to sensitive information stored in the database. This is possible because the plugin does not properly escape user supplied parameters and does not adequately prepare the SQL query.

Detected in:

LetsRecover – WooCommerce Abandoned Cart Notifications fixed vulnerable versions: >= * <= 1.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.