PT-2026-86363 · WordPress · Abandoned Cart Pro For Woocommerce
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Abandoned Cart Pro for WooCommerce versions prior to 10.7.2
Description
Privilege escalation is possible for authenticated users with subscriber-level access and above. The issue stems from missing capability checks and nonce verification—a security token used to prevent cross-site request forgery—on several AJAX actions: 'wcap save connector settings', 'wcap send manual email', 'wcap abandoned cart info', and 'wcap change manual email data'. Attackers can modify SMTP connector settings to route administrator recovery emails through a server they control, allowing them to intercept auto-login links and obtain full administrative access. This requires the auto-login feature to be enabled, which is the default setting.
Recommendations
Update Abandoned Cart Pro for WooCommerce to version 10.7.2 or later.
As a temporary mitigation, disable the auto-login feature.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abandoned Cart Pro For Woocommerce