PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81543 Tyche Softwares CVE debrief

The Abandoned Cart Pro for WooCommerce plugin for WordPress has a privilege escalation vulnerability in all versions up to, and including, 10.7.1. Authenticated attackers with subscriber-level access and above can modify SMTP connector settings to intercept administrator recovery emails and auto-login links, potentially gaining full administrative access if the plugin's auto-login feature is enabled.

Vendor
Tyche Softwares
Product
Abandoned Cart Pro for WooCommerce
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-05
Original CVE updated
2026-09-07
Advisory published
2026-09-05
Advisory updated
2026-09-07

Who should care

Defenders responsible for WordPress installations with the Abandoned Cart Pro for WooCommerce plugin should assess their exposure and take necessary actions to secure their systems.

Why it matters

CVE-2026-81543 is a privilege escalation vulnerability in the Abandoned Cart Pro for WooCommerce plugin for WordPress. Defenders should care because it allows authenticated attackers to modify SMTP connector settings and potentially gain administrative access. The vulnerability requires verification of the plugin's presence, configuration, and proper securing of SMTP settings.

  • Potential interception of administrator recovery emails
  • Potential gain of full administrative access through auto-login links
  • Necessity to verify plugin configuration and update to the latest version
  • Importance to monitor SMTP connector settings for suspicious activity

Technical summary

The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing capability checks and nonce verification on multiple AJAX actions. This allows authenticated attackers with subscriber-level access and above to modify SMTP connector settings and potentially gain full administrative access if the plugin's auto-login feature is enabled. The plugin's default configuration enables the auto-login feature, which could be exploited if not properly secured. Defenders should prioritize verifying the presence of this plugin, assessing the configuration of the auto-login feature, and ensuring that SMTP connector settings are properly secured.

Defensive priority

Defenders should prioritize verifying the presence of this plugin, assessing the configuration of the auto-login feature, and ensuring that SMTP connector settings are properly secured.

Recommended defensive actions

  • Verify the presence and version of the Abandoned Cart Pro for WooCommerce plugin
  • Assess the configuration of the auto-login feature and disable it if not necessary
  • Ensure that SMTP connector settings are properly secured and monitored
  • Review and update the plugin to the latest version if vulnerable
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability is due to missing capability checks and nonce verification on multiple AJAX actions. The plugin's default configuration enables the auto-login feature, which could be exploited if not properly secured.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81543 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81543

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81543 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81543

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.