THREAT OPS › Threat News › [NVD] CVE-2026-81543 (HIGH 8.8) — The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_se
[NVD] CVE-2026-81543 (HIGH 8.8) — The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_se
CVE-2026-81543 CVSS: 8.8 HIGH Published: 2026-09-05T08:16:40.730
The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_ch
Indicators of compromise
- CVE-2026-81543cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81543