๐Ÿ” CVE Alert

CVE-2025-26899

UNKNOWN 0.0

WordPress Recapture for WooCommerce Plugin <= 1.0.43 - CSRF to Settings Change vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cross-Site Request Forgery (CSRF) vulnerability in Recapture Cart Recovery and Email Marketing Recapture for WooCommerce recapture-for-woocommerce allows Cross Site Request Forgery.This issue affects Recapture for WooCommerce: from n/a through <= 1.0.43.

CWE CWE-352
Vendor recapture cart recovery and email marketing
Product recapture for woocommerce
Published Mar 15, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for recapture cart recovery and email marketing recapture for woocommerce

Be the first to know when new unknown vulnerabilities affecting recapture cart recovery and email marketing recapture for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Recapture Cart Recovery and Email Marketing / Recapture for WooCommerce
0 โ‰ค 1.0.43

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/recapture-for-woocommerce/vulnerability/wordpress-recapture-for-woocommerce-plugin-1-0-43-csrf-to-settings-change-vulnerability?_s_id=cve

Credits

Nguyen Xuan Chien | Patchstack Bug Bounty Program