HIGH
Tyche Softwares
CVE published 2026-09-05
CVE-2026-81543
The Abandoned Cart Pro for WooCommerce plugin for WordPress has a privilege escalation vulnerability in all versions up to, and including, 10.7.1. Authenticated attackers with subscriber-level access and above can modify SMTP connector settings to intercept administrator recovery emails and auto-login links, potentially gaining full administrative access if the plugin's auto-login feature is enabled.