CVE-2026-66682: WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Affected Software
1 affected component
WordPress plugin Abandoned Cart Pro for WooCommerce<=10.4.0
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or any existing privileges to exploit it.
2
Which installations are affected?
Installations using Abandoned Cart Pro for WooCommerce version 10.4.0 or earlier are affected according to the available information.
3
What is the likely impact of successful exploitation?
Successful exploitation can result in privilege escalation. The supplied CVSS vector indicates high impact to confidentiality, integrity, and availability.