The Abandoned Cart Lite and Abandoned Cart Pro plugins for WordPress are vulnerable to a type of attack called Stored Cross-Site Scripting. This means that malicious code could be inserted into user input, which would then be executed on the admin dashboard. These vulnerabilities exist in versions up to 5.1.3 and 7.12.0 of the plugins, and are caused by a lack of security measures which are meant to protect user input from being exploited.