ZeroHour

CVE-2026-81543

large

Authenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce (<= 10.7.1)

CVSS 3.1
8.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-81543 is a privilege-escalation flaw in the Abandoned Cart Pro for WooCommerce WordPress plugin: several of its AJAX actions (wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data) lack capability checks and nonce verification. Any logged-in user with subscriber-level access or above can therefore invoke these actions, for example rewriting the plugin's SMTP connector settings so that the store's administrator recovery emails are routed through an attacker-controlled mail server. With the plugin's auto-login feature enabled (its default configuration), the attacker can then trigger a recovery email, capture the auto-login link it contains, and use it to obtain full administrator access to the site. Any WordPress site running the plugin in versions up to and including 10.7.1 is affected, provided it has at least one subscriber-level account, which is effectively every WooCommerce store with customer registration. No public proof-of-concept or confirmed in-the-wild exploitation is known, and EPSS currently assigns roughly a 0.2% probability of exploitation within 30 days.

What to do: Update Abandoned Cart Pro for WooCommerce to a release newer than 10.7.1 on every store where the plugin is active. Until patched, disable the plugin's auto-login feature, restrict or vet subscriber registrations, and verify that the SMTP connector settings have not been altered. Also review recent administrator password-reset/recovery emails and admin logins for signs that auto-login links were intercepted.

Affected
Tyche Softwares Abandoned Cart Pro for WooCommerce (WordPress plugin)all versions up to and including 10.7.1 (<= 10.7.1)
Estimated exposure
largeroughly 10,000-30,000 WooCommerce sites (premium plugin, no public install count) — This is a paid Pro-tier plugin with no WordPress.org active-install listing, so the estimate is derived from the vendor's 10,000+ customer claim and the free Lite edition's roughly 30,000 active installs, placing the paid tier's footprint…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify SMTP connector settings to route administrator recovery emails through an attacker-controlled server and intercept auto-login links to gain full administrative access. The plugin's auto-login feature must be enabled, which is the default configuration.

Ecosystems
WordPress, E-commerce
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.