CVE-2026-81543
Received Received - Intake

Privilege Escalation in Abandoned Cart Pro for WooCommerce

Vulnerability report for CVE-2026-81543, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: Wordfence

Description

The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify SMTP connector settings to route administrator recovery emails through an attacker-controlled server and intercept auto-login links to gain full administrative access. The plugin's auto-login feature must be enabled, which is the default configuration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tyche_softwares abandoned_cart_pro_for_woocommerce to 10.7.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Abandoned Cart Pro for WooCommerce plugin for WordPress has a privilege escalation vulnerability in versions up to 10.7.1. It lacks proper capability checks and nonce verification on certain AJAX actions. This allows authenticated attackers with subscriber-level access or higher to modify SMTP settings and intercept admin recovery emails or auto-login links, potentially gaining full administrative access.

Detection Guidance

Check for unauthorized changes in SMTP connector settings or email routing configurations in the Abandoned Cart Pro for WooCommerce plugin. Review server logs for unusual SMTP traffic or intercepted emails. Inspect WordPress user roles for unauthorized privilege escalations.

Impact Analysis

If exploited, attackers could route administrator emails through their server, intercept auto-login links, and gain full admin access to the WordPress site. This could lead to data theft, site defacement, or further compromise of user accounts and sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Compliance failures may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Update the Abandoned Cart Pro for WooCommerce plugin to the latest version beyond 10.7.1. Disable the auto-login feature if enabled. Implement strong access controls for WordPress user roles. Monitor SMTP settings and email routing for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81543. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart