Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce
CVE-2026-66682
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-66682?
An unauthenticated privilege escalation vulnerability exists in the Abandoned Cart Pro plugin for WooCommerce, specifically in versions 10.4.0 and earlier. This vulnerability can potentially allow attackers to escalate their privileges without authentication, exposing sensitive user data and administrative functionalities, which may lead to further exploitation.
Affected Version(s)
Abandoned Cart Pro for WooCommerce <= 10.4.0