{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3atyche_softwaresabandoned_cart_pro_for_woocommerce/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tyche_softwares:abandoned_cart_pro_for_woocommerce:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-81543"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Abandoned Cart Pro for WooCommerce (\u003c= 10.7.1)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","wordpress","plugin","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Tyche Softwares"],"content_html":"\u003cp\u003eThe Abandoned Cart Pro for WooCommerce plugin for WordPress, developed by Tyche Softwares, contains a critical privilege escalation vulnerability (CVE-2026-81543) affecting all versions up to and including 10.7.1. The flaw stems from missing capability checks and nonce verification within several AJAX actions, specifically wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data.\u003c/p\u003e\n\u003cp\u003eAn attacker with authenticated subscriber-level access can exploit these deficiencies to modify SMTP connector settings. By redirecting outgoing administrative emails through an attacker-controlled server, the actor can intercept account recovery emails and auto-login links. If the plugin's default auto-login feature is active, this allows the attacker to gain full administrative privileges on the WordPress site. Defenders should note that this vulnerability requires an authenticated session and targets the plugin's default email management functions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a subscriber-level user to escalate privileges to a full administrator account. This grants the attacker complete control over the WordPress installation, enabling them to install malicious plugins, exfiltrate customer databases, or modify site content. The vulnerability impacts all users of the affected plugin versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Abandoned Cart Pro for WooCommerce plugin to the latest version (or the version containing the fix provided by Tyche Softwares) immediately.\u003c/li\u003e\n\u003cli\u003eAudit existing SMTP connector settings in the plugin for any unauthorized or unfamiliar external mail relay configurations.\u003c/li\u003e\n\u003cli\u003eMonitor WordPress access logs for high-frequency or unauthorized calls to the identified AJAX action endpoints from users without administrative roles.\u003c/li\u003e\n\u003cli\u003eDisable the auto-login feature within the plugin settings until a patch is applied to mitigate the risk of account hijacking via intercepted links.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T09:30:51Z","date_published":"2026-09-05T09:30:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-81543/","summary":"The Abandoned Cart Pro for WooCommerce plugin is vulnerable to privilege escalation allowing authenticated subscribers to hijack administrative accounts by intercepting SMTP settings and email recovery tokens.","title":"Privilege Escalation in Abandoned Cart Pro for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-81543/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:tyche_softwares:abandoned_cart_pro_for_woocommerce:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}