<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:tyche_softwares:abandoned_cart_pro_for_woocommerce:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3atyche_softwaresabandoned_cart_pro_for_woocommerce/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 05 Sep 2026 09:30:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3atyche_softwaresabandoned_cart_pro_for_woocommerce/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation in Abandoned Cart Pro for WooCommerce</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-81543/</link><pubDate>Sat, 05 Sep 2026 09:30:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-81543/</guid><description>The Abandoned Cart Pro for WooCommerce plugin is vulnerable to privilege escalation allowing authenticated subscribers to hijack administrative accounts by intercepting SMTP settings and email recovery tokens.</description><content:encoded><![CDATA[<p>The Abandoned Cart Pro for WooCommerce plugin for WordPress, developed by Tyche Softwares, contains a critical privilege escalation vulnerability (CVE-2026-81543) affecting all versions up to and including 10.7.1. The flaw stems from missing capability checks and nonce verification within several AJAX actions, specifically wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data.</p>
<p>An attacker with authenticated subscriber-level access can exploit these deficiencies to modify SMTP connector settings. By redirecting outgoing administrative emails through an attacker-controlled server, the actor can intercept account recovery emails and auto-login links. If the plugin's default auto-login feature is active, this allows the attacker to gain full administrative privileges on the WordPress site. Defenders should note that this vulnerability requires an authenticated session and targets the plugin's default email management functions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a subscriber-level user to escalate privileges to a full administrator account. This grants the attacker complete control over the WordPress installation, enabling them to install malicious plugins, exfiltrate customer databases, or modify site content. The vulnerability impacts all users of the affected plugin versions.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Abandoned Cart Pro for WooCommerce plugin to the latest version (or the version containing the fix provided by Tyche Softwares) immediately.</li>
<li>Audit existing SMTP connector settings in the plugin for any unauthorized or unfamiliar external mail relay configurations.</li>
<li>Monitor WordPress access logs for high-frequency or unauthorized calls to the identified AJAX action endpoints from users without administrative roles.</li>
<li>Disable the auto-login feature within the plugin settings until a patch is applied to mitigate the risk of account hijacking via intercepted links.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>wordpress</category><category>plugin</category><category>web-vulnerability</category></item></channel></rss>