CVE-2026-14829: Unknown Checkimate — Woocommerce Checkout, Abandoned Cart Recovery & Order Bumps

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13's premium licensing state and erase the stored license key.

Affected products

  • Unknown Checkimate — Woocommerce Checkout, Abandoned Cart Recovery & Order Bumps: up to and including 1.0.13

Published 2026-08-06. Last modified 2026-08-26.