Impact
An unauthenticated flaw in Abandoned Cart Pro for WooCommerce allows an attacker to elevate privileges within a WordPress site, effectively granting administrative rights without credentials. The privilege escalation, identified as CWE-266, could enable full control over the website, including modifying settings, accessing sensitive data, or installing additional malware.
Affected Systems
The vulnerability impacts the Tyche Softwares product Abandoned Cart Pro for WooCommerce, affecting all releases up to and including version 10.4.0. Earlier versions of other WordPress plugins are unaffected.
Risk and Exploitability
The CVSS base score of 9.8 marks this flaw as critical, and the absence of an EPSS score or KEV listing does not lower its risk, given the unauthenticated nature of the attack. The CVE description does not specify the attack vector; it is inferred that a remote HTTP request to the plugin's endpoint could be one possible vector, but this is not explicitly documented in the advisory.
OpenCVE Enrichment