CVE-2026-66682: pre-auth privilege escalation in Tyche Softwares Abandoned Cart Pro for WooCommerce

An unauthenticated attacker can escalate privileges in Abandoned Cart Pro for WooCommerce, potentially gaining elevated control over the plugin and its data; this is CVE-2026-66682. The issue affects Abandoned Cart Pro for WooCommerce version 10.4.0 and earlier (branch 10.x). No authentication is required to exploit the flaw, so only network access to a site running the plugin is necessary.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00483
CWE
CWE-266
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a high-impact pre-auth privilege escalation that requires no login, so treat internet-facing sites running the plugin as high priority to protect until a vendor fix is released.

What is CVE-2026-66682?

An unauthenticated attacker can escalate privileges in Abandoned Cart Pro for WooCommerce, potentially gaining elevated control over the plugin and its data; this is CVE-2026-66682. The issue affects Abandoned Cart Pro for WooCommerce version 10.4.0 and earlier (branch 10.x). No authentication is required to exploit the flaw, so only network access to a site running the plugin is necessary.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Tyche Softwares Abandoned Cart Pro for WooCommerce are affected?

BRANCHAFFECTEDFIXED
10.x10.4.0 and earlier

Is CVE-2026-66682 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-66682

  1. If possible, disable the Abandoned Cart Pro for WooCommerce plugin until a vendor fix is available.
  2. Restrict access to affected sites by firewall rules or IP allowlists to limit exposure of the plugin.
  3. Monitor web and application logs for anomalous activity related to the plugin and privilege changes.
  4. Apply the vendor's official patch or upgrade instructions immediately when they are released.

Frequently asked questions

Is CVE-2026-66682 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which Abandoned Cart Pro for WooCommerce versions are affected by CVE-2026-66682?

Abandoned Cart Pro for WooCommerce versions 10.4.0 and earlier (branch 10.x) are affected.

Is there a patch for CVE-2026-66682?

No fixed version is listed; the vendor has not published a fixed release as of 2026-09-29, so follow vendor guidance and mitigation steps until a patch is available.

Does CVE-2026-66682 require authentication?

No, CVE-2026-66682 is an unauthenticated privilege escalation that does not require a valid user login to exploit.

References