PT-2026-86363 · WordPress · Abandoned Cart Pro For Woocommerce

·

CVE-2026-81543

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Abandoned Cart Pro for WooCommerce versions prior to 10.7.2
Description Privilege escalation is possible for authenticated users with subscriber-level access and above. The issue stems from missing capability checks and nonce verification—a security token used to prevent cross-site request forgery—on several AJAX actions: 'wcap save connector settings', 'wcap send manual email', 'wcap abandoned cart info', and 'wcap change manual email data'. Attackers can modify SMTP connector settings to route administrator recovery emails through a server they control, allowing them to intercept auto-login links and obtain full administrative access. This requires the auto-login feature to be enabled, which is the default setting.
Recommendations Update Abandoned Cart Pro for WooCommerce to version 10.7.2 or later. As a temporary mitigation, disable the auto-login feature.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81543

Affected Products

Abandoned Cart Pro For Woocommerce