The Abandoned Cart Pro for WooCommerce plugin has a security flaw that allows an attacker to upload any type of file to a website using the plugin. This vulnerability exists in all versions of the plugin up to version 9.16.0. An attacker with at least subscriber-level access can exploit this vulnerability to upload files to the website’s server. Depending on the server’s settings, this could potentially lead to remote or local code execution.