DIRAS TAKE
Urgent: this is a high-impact pre-auth privilege escalation that requires no login, so treat internet-facing sites running the plugin as high priority to protect until a vendor fix is released.
What is CVE-2026-66682?
An unauthenticated attacker can escalate privileges in Abandoned Cart Pro for WooCommerce, potentially gaining elevated control over the plugin and its data; this is CVE-2026-66682. The issue affects Abandoned Cart Pro for WooCommerce version 10.4.0 and earlier (branch 10.x). No authentication is required to exploit the flaw, so only network access to a site running the plugin is necessary.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Tyche Softwares Abandoned Cart Pro for WooCommerce are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 10.x | 10.4.0 and earlier |
Is CVE-2026-66682 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-66682
- If possible, disable the Abandoned Cart Pro for WooCommerce plugin until a vendor fix is available.
- Restrict access to affected sites by firewall rules or IP allowlists to limit exposure of the plugin.
- Monitor web and application logs for anomalous activity related to the plugin and privilege changes.
- Apply the vendor's official patch or upgrade instructions immediately when they are released.
Frequently asked questions
Is CVE-2026-66682 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which Abandoned Cart Pro for WooCommerce versions are affected by CVE-2026-66682?
Abandoned Cart Pro for WooCommerce versions 10.4.0 and earlier (branch 10.x) are affected.
Is there a patch for CVE-2026-66682?
No fixed version is listed; the vendor has not published a fixed release as of 2026-09-29, so follow vendor guidance and mitigation steps until a patch is available.
Does CVE-2026-66682 require authentication?
No, CVE-2026-66682 is an unauthenticated privilege escalation that does not require a valid user login to exploit.
References
- nvd.nist.gov/vuln/detail/CVE-2026-66682
- cve.org/CVERecord?id=CVE-2026-66682
- patchstack.com/database/wordpress/plugin/woocommerce-abandon-cart-pro/vulnerability/wordpress-abandoned-cart-pro-for-woocommerce-plugin-10-4-0-privilege-escalation-vulnerability-2?_s_id=cve
- All Tyche Softwares CVEs on CVE Radar
- CVEs published in September 2026