The Abandoned Cart Lite plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery in all versions up to, and including, 5.16.1. This means that attackers who are not logged in may be able to do things like dismiss notifications and change template statuses if they can fool a site administrator into clicking on a link. To protect your site, you should ensure that you have the latest version of the plugin installed.