BeyondCart Connector

BeyondCart Connector has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is Use Of Hard-Coded Credentials, behind 1 of the records (100%).

The one issue recorded for BeyondCart Connector has a vendor fix available, so running the current release closes it.

All of these findings were reported by kr0d. BeyondCart Connector is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all BeyondCart Connector vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2025-8570

BeyondCart Connector <= 3.0.1 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter

Read the full analysis

Vulnerability Records

1 records
BeyondCart Connector banner
Latestv3.1.2

BeyondCart Connector

beyondcart

Author

beyondcart

0.0(0)
0/100
Last Updated
2025-11-20 (10mo ago)
Active Installs
10+
Downloads
3,056
Requires WP
0+
Requires PHP
7.4+
Tested up to
WP 6.8.8
Created
2023-05-12 (3y ago)

Turn One-time Shoppers into Reccuring Revenue Connector to BeyondCart – SaaS product that transform your eCommerce to a mobile app instantly and build customers for life! Analyze their behavior and drive repeat sales with targeted push notifications. Build customersfor life Make users stick around and drive repeat purchases with a Mobile Shopping App and Customer Engagement Platform Boost your business with a Mobile Shopping App Engage shoppers where they’re most likely to convert – their phone. Offer a personalized shopping experience that keep cusomers ready to buy. Offer users an ultimate experience that help them find easily what they want wherever they are. Your mobile shopping app is full with features that will retain your customers and will help you build community for a lifetime Drive sustainable growth with Customer Engagment Platform Use our customer engagement platform to ultimate your targeting strategy and drive repeat sales with the power of push notifications. While users interact with your mobile shopping app our customer engagement platform records their in-app behaviour. The details of every session logged are used to form the isights you need to drive sales Push notifications center Drive sales and repeat purchases by sending data-driven push notifications based on customer in-app behaviour, preferences and purchase patterns. Beyond Cart is super easy to integrate with your online store ✔ Our team of experts converts your store to a fully branded Android and iOS Shopping App ✔ We handle the app submission and publishing process, so there is nothing new to figure out ✔ After your app becomes available in the app stores we will support you to ensure the success of your project Our website: Any questions? Visit our website beyondcart.com External Services This plugin relies on 3rd party services for its &#8216;Sign in with Apple’, &#8216;Login with Google’, and &#8216;Login with Facebook’ features: Sign in with Apple Apple’s authentication servers are contacted to fetch public keys for verifying JSON Web Tokens (JWT) when users sign in with their Apple IDs. Apple’s authentication server URL: https://appleid.apple.com/auth/keys Apple’s Privacy Policy: https://www.apple.com/legal/privacy/en-ww/ Apple’s Terms of Use: https://www.apple.com/legal/internet-services/terms/site.html Login with Google Google’s authentication servers are contacted when users sign in with their Google accounts. Google API Console: https://console.developers.google.com/ Google’s Privacy Policy: https://policies.google.com/privacy Google’s Terms of Service: https://policies.google.com/terms Login with Facebook Facebook’s authentication servers are contacted when users sign in with their Facebook accounts. Facebook for Developers: https://developers.facebook.com/ Facebook’s Data Policy: https://www.facebook.com/policy.php Facebook’s Terms of Service: https://www.facebook.com/terms.php

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C