BeyondCart Connector
BeyondCart Connector has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Use Of Hard-Coded Credentials, behind 1 of the records (100%).
The one issue recorded for BeyondCart Connector has a vendor fix available, so running the current release closes it.
All of these findings were reported by kr0d. BeyondCart Connector is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-8570BeyondCart Connector <= 3.0.1 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter
Read the full analysisVulnerability Records

BeyondCart Connector
Author
beyondcart
Turn One-time Shoppers into Reccuring Revenue Connector to BeyondCart – SaaS product that transform your eCommerce to a mobile app instantly and build customers for life! Analyze their behavior and drive repeat sales with targeted push notifications. Build customersfor life Make users stick around and drive repeat purchases with a Mobile Shopping App and Customer Engagement Platform Boost your business with a Mobile Shopping App Engage shoppers where they’re most likely to convert – their phone. Offer a personalized shopping experience that keep cusomers ready to buy. Offer users an ultimate experience that help them find easily what they want wherever they are. Your mobile shopping app is full with features that will retain your customers and will help you build community for a lifetime Drive sustainable growth with Customer Engagment Platform Use our customer engagement platform to ultimate your targeting strategy and drive repeat sales with the power of push notifications. While users interact with your mobile shopping app our customer engagement platform records their in-app behaviour. The details of every session logged are used to form the isights you need to drive sales Push notifications center Drive sales and repeat purchases by sending data-driven push notifications based on customer in-app behaviour, preferences and purchase patterns. Beyond Cart is super easy to integrate with your online store ✔ Our team of experts converts your store to a fully branded Android and iOS Shopping App ✔ We handle the app submission and publishing process, so there is nothing new to figure out ✔ After your app becomes available in the app stores we will support you to ensure the success of your project Our website: Any questions? Visit our website beyondcart.com External Services This plugin relies on 3rd party services for its ‘Sign in with Apple’, ‘Login with Google’, and ‘Login with Facebook’ features: Sign in with Apple Apple’s authentication servers are contacted to fetch public keys for verifying JSON Web Tokens (JWT) when users sign in with their Apple IDs. Apple’s authentication server URL: https://appleid.apple.com/auth/keys Apple’s Privacy Policy: https://www.apple.com/legal/privacy/en-ww/ Apple’s Terms of Use: https://www.apple.com/legal/internet-services/terms/site.html Login with Google Google’s authentication servers are contacted when users sign in with their Google accounts. Google API Console: https://console.developers.google.com/ Google’s Privacy Policy: https://policies.google.com/privacy Google’s Terms of Service: https://policies.google.com/terms Login with Facebook Facebook’s authentication servers are contacted when users sign in with their Facebook accounts. Facebook for Developers: https://developers.facebook.com/ Facebook’s Data Policy: https://www.facebook.com/policy.php Facebook’s Terms of Service: https://www.facebook.com/terms.php
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C