Software intelligence
Important: Cart Lift appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
4
Latest advisory
8 July 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
cart-lift
Plugin
This catalog lists 4 known advisories affecting Cart Lift. The most recent was published on 8 July 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD <= 3.1.57 - Unauthenticated Stored Cross-Site Scripting
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 8 July 2026
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD <= 3.1.5 - Reflected Cross-Site Scripting via cart_search
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 2 March 2023
Appsero <= 1.2.1 - Missing Authorization
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Published 16 December 2022
Known Cart Lift advisories published by month.
CVE-2026-57417 · Published 8 July 2026
Affected versions: ≤ 3.1.57
CVE-2022-47449 · Published 2 March 2023
Affected versions: ≤ 3.1.5
No CVE assigned · Published 16 December 2022
Affected versions: ≤ 3.1.3
CVE-2022-47150 · Published 14 December 2022
Affected versions: ≤ 3.1.3
SiteRespond Defence matches your installed Cart Lift version against this catalog when the Defence plugin is connected to your WordPress site.