Executive brief
A security vulnerability in the WooCommerce Cart Abandonment Recovery plugin allows users with 'Shop Manager' roles to gain unauthorized administrative control over the website. This plugin is used by e-commerce sites to track and recover lost sales from abandoned shopping carts. If exploited, a malicious staff member or an attacker who has compromised a shop manager account could take full control of the site, potentially leading to data theft or site defacement.
Technical details
The WooCommerce Cart Abandonment Recovery plugin for WordPress (versions prior to 2.1.0) contains a privilege escalation vulnerability classified as Incorrect Privilege Assignment (CWE-266). The flaw allows an authenticated user with the 'Shop Manager' role to escalate their privileges to 'Administrator' due to insufficient permission checks within the plugin's functionality. This is a network-based attack that requires high privileges (Shop Manager) but no user interaction. Successful exploitation grants the attacker full control over the WordPress environment. The issue is resolved in version 2.1.0.
Affected products
- Brainstorm Force WooCommerce Cart Abandonment Recovery < 2.1.0
Timeline
- 2026-01-26: other: Reported by Nguyen Ba Khanh
- 2026-04-08: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date