CVE-2026-81543
- EPSS 0.25%
- Veröffentlicht 05.09.2026 07:38:15
- Zuletzt bearbeitet 08.09.2026 13:12:58
The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_sa...
CVE-2026-66682
- EPSS -
- Veröffentlicht 20.08.2026 12:16:36
- Zuletzt bearbeitet 20.08.2026 17:19:29
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVE-2026-56010
- EPSS 0.38%
- Veröffentlicht 26.06.2026 14:52:29
- Zuletzt bearbeitet 26.06.2026 21:16:35
Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVE-2025-4387
- EPSS 0.47%
- Veröffentlicht 10.06.2025 03:41:37
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in the wcap_add_to_cart_popup_upload_files function in all versions up to, and including, 9.16.0. This mak...
CVE-2019-25152
- EPSS 1.36%
- Veröffentlicht 22.06.2023 02:15:47
- Zuletzt bearbeitet 08.04.2026 19:17:33
The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insuffi...