9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 2.1.0. This makes it possible for unauthenticated attackers to craft valid tokens and assume any userβs identity.
Basic Information
ID
CVE-2025-8570
Source
Wordfence
Published
Sep 11, 2025 at 07:24
Modified
Sep 11, 2025 at 14:37
Affected Product
Vendor
beyondcart
Product
BeyondCart Connector
Version
*
Affected Versions
beyondcart BeyondCart Connector *