The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13's premium licensing state and erase the stored license key.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Thu, 06 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13's premium licensing state and erase the stored license key. | |
| Title | Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-06T06:00:11.378Z
Reserved: 2026-07-06T09:08:34.459Z
Link: CVE-2026-14829
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T07:30:16Z