The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to a type of attack called SQL Injection up to version 5.8.2. This attack takes advantage of a flaw in the plugin which does not appropriately secure user-provided information and does not properly prepare existing SQL queries. This allows unauthenticated attackers to add malicious queries to an already existing query, potentially gaining access to sensitive information from the database.