Executive brief
Abandoned Cart Pro for WooCommerce, a WordPress plugin used to recover lost sales by tracking unfinished checkouts, contains a security flaw that allows low-privileged users to increase their own permissions. An attacker with a basic 'Subscriber' account could exploit this to gain administrative control over the website. This could lead to full site takeover, theft of customer data, or disruption of store operations.
Technical details
A privilege escalation vulnerability exists in the Abandoned Cart Pro for WooCommerce plugin for WordPress due to incorrect privilege assignment (CWE-266). The flaw allows an authenticated attacker with Subscriber-level permissions to escalate their privileges to a higher level, potentially gaining full administrative access to the WordPress site. The vulnerability is reachable over the network and does not require user interaction. The issue is resolved in version 10.4.1.
Affected products
- Tyche Softwares Abandoned Cart Pro for WooCommerce <= 10.4.0
Timeline
- 2026-05-15: disclosed: Reported by Austin Ginder
- 2026-06-19: advisory: Patchstack published advisory
- 2026-06-26: patched: NVD published date and patch availability confirmed in 10.4.1