PatchSiren cyber security CVE debrief
CVE-2026-81543 Tyche Softwares CVE debrief
The Abandoned Cart Pro for WooCommerce plugin for WordPress has a privilege escalation vulnerability in all versions up to, and including, 10.7.1. Authenticated attackers with subscriber-level access and above can modify SMTP connector settings to intercept administrator recovery emails and auto-login links, potentially gaining full administrative access if the plugin's auto-login feature is enabled.
- Vendor
- Tyche Softwares
- Product
- Abandoned Cart Pro for WooCommerce
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-05
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-05
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for WordPress installations with the Abandoned Cart Pro for WooCommerce plugin should assess their exposure and take necessary actions to secure their systems.
Why it matters
CVE-2026-81543 is a privilege escalation vulnerability in the Abandoned Cart Pro for WooCommerce plugin for WordPress. Defenders should care because it allows authenticated attackers to modify SMTP connector settings and potentially gain administrative access. The vulnerability requires verification of the plugin's presence, configuration, and proper securing of SMTP settings.
- Potential interception of administrator recovery emails
- Potential gain of full administrative access through auto-login links
- Necessity to verify plugin configuration and update to the latest version
- Importance to monitor SMTP connector settings for suspicious activity
Technical summary
The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing capability checks and nonce verification on multiple AJAX actions. This allows authenticated attackers with subscriber-level access and above to modify SMTP connector settings and potentially gain full administrative access if the plugin's auto-login feature is enabled. The plugin's default configuration enables the auto-login feature, which could be exploited if not properly secured. Defenders should prioritize verifying the presence of this plugin, assessing the configuration of the auto-login feature, and ensuring that SMTP connector settings are properly secured.
Defensive priority
Defenders should prioritize verifying the presence of this plugin, assessing the configuration of the auto-login feature, and ensuring that SMTP connector settings are properly secured.
Recommended defensive actions
- Verify the presence and version of the Abandoned Cart Pro for WooCommerce plugin
- Assess the configuration of the auto-login feature and disable it if not necessary
- Ensure that SMTP connector settings are properly secured and monitored
- Review and update the plugin to the latest version if vulnerable
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is due to missing capability checks and nonce verification on multiple AJAX actions. The plugin's default configuration enables the auto-login feature, which could be exploited if not properly secured.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81543 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81543
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81543 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81543
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://woocommerce.com/products/abandoned-cart-pro/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.