PT-2026-49376 · Brainstorm Force+1 · Recover Woocommerce Cart Abandonment+1

CVE-2026-39470

·

Published

2026-04-08

·

Updated

2026-06-15

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cart Abandonment Recovery for WooCommerce versions prior to 2.1.0
Description An issue exists in the Cart Abandonment Recovery for WooCommerce plugin for WordPress that allows authenticated attackers with Shop Manager-level access or higher to escalate their privileges to those of an administrator.
Recommendations Update to version 2.1.0 or later.

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39470

Affected Products

Recover Woocommerce Cart Abandonment
Woo-Cart-Abandonment-Recovery