CVE-2026-81543
largeAuthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce (<= 10.7.1)
CVE-2026-81543 is a privilege-escalation flaw in the Abandoned Cart Pro for WooCommerce WordPress plugin: several of its AJAX actions (wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data) lack capability checks and nonce verification. Any logged-in user with subscriber-level access or above can therefore invoke these actions, for example rewriting the plugin's SMTP connector settings so that the store's administrator recovery emails are routed through an attacker-controlled mail server. With the plugin's auto-login feature enabled (its default configuration), the attacker can then trigger a recovery email, capture the auto-login link it contains, and use it to obtain full administrator access to the site. Any WordPress site running the plugin in versions up to and including 10.7.1 is affected, provided it has at least one subscriber-level account, which is effectively every WooCommerce store with customer registration. No public proof-of-concept or confirmed in-the-wild exploitation is known, and EPSS currently assigns roughly a 0.2% probability of exploitation within 30 days.
What to do: Update Abandoned Cart Pro for WooCommerce to a release newer than 10.7.1 on every store where the plugin is active. Until patched, disable the plugin's auto-login feature, restrict or vet subscriber registrations, and verify that the SMTP connector settings have not been altered. Also review recent administrator password-reset/recovery emails and admin logins for signs that auto-login links were intercepted.
| Tyche Softwares Abandoned Cart Pro for WooCommerce (WordPress plugin) | all versions up to and including 10.7.1 (<= 10.7.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify SMTP connector settings to route administrator recovery emails through an attacker-controlled server and intercept auto-login links to gain full administrative access. The plugin's auto-login feature must be enabled, which is the default configuration.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.