CVE-2026-14829
Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13's premium licensing state and erase the stored license key.
| Vendor | unknown |
| Product | checkimate — woocommerce checkout, abandoned cart recovery & order bumps |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown checkimate — woocommerce checkout, abandoned cart recovery & order bumps
Be the first to know when new unknown vulnerabilities affecting unknown checkimate — woocommerce checkout, abandoned cart recovery & order bumps are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps
0 ≤ 1.0.13
References
Credits
Pedro Pinho WPScan