Executive brief
Abandoned Cart Pro for WooCommerce is a plugin that helps online stores recover lost sales by targeting customers who abandon their shopping carts. An unauthenticated attacker can exploit this vulnerability to gain full administrator access to a WordPress site, leading to complete site compromise, customer data theft, malware injection, and operational disruption. No official patch is currently available.
Technical details
This is an unauthenticated privilege escalation vulnerability in the Abandoned Cart Pro for WooCommerce plugin versions 10.4.0 and earlier. The vulnerability allows an unprivileged or unauthenticated attacker to escalate privileges and gain full administrative control. The root cause stems from improper authentication or authorization checks in the plugin's code (classified as an identification and authentication failure under OWASP A7). Since the vulnerability requires no authentication or user interaction, it is accessible over the network to any attacker. Successful exploitation grants full admin access to the WordPress installation, enabling complete site takeover. No official patch has been released as of August 2026, though Patchstack has provided mitigation rules to block known attack patterns.
Affected products
- WP-Staging Abandoned Cart Pro for WooCommerce <=10.4.0
Timeline
- 2026-08-20: disclosed: Published on Patchstack
- 2026-05-15: reported: Reported by Austin Ginder