Impact
The Abandoned Cart Pro plugin for WooCommerce contains missing capability checks and nonce verification on several AJAX actions. The flaw allows an authenticated user with a subscriber role or higher to modify SMTP connector settings and intercept administrator recovery emails. This can lead to complete administrative control of the WordPress site. The vulnerability is a classic privilege escalation weakness identified as CWE‑269.
Affected Systems
Tyche Softwares’ Abandoned Cart Pro for WooCommerce versions 10.7.1 and earlier are impacted. No specific sub‑versions are listed, so all releases up to and including 10.7.1 should be considered vulnerable. Users running any of these versions must review the plugin configuration and assess whether the auto‑login feature is enabled, as it is required for the exploitation path.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS is not available, so the likelihood of exploitation cannot be quantified, but the vulnerability is not listed in CISA KEV, suggesting no confirmed exploit activity yet. The attack vector is inferred to be through authenticated AJAX requests to the plugin’s endpoints. An attacker only needs a subscriber or higher role and the auto‑login feature enabled, both of which are common defaults. If those conditions are met, the attacker can gain full administrative access.
OpenCVE Enrichment