THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-81543 (HIGH 8.8) — The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_se

[NVD] CVE-2026-81543 (HIGH 8.8) — The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_se

mednvdPublished 2026-09-05

CVE-2026-81543 CVSS: 8.8 HIGH Published: 2026-09-05T08:16:40.730

The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_ch

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81543