BeyondCart Connector <= 3.0.1 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter

2025-09-10 18:48
kr0d

Strategic Overview

Status
Patched in 3.0.2
Affected PluginBeyondCart Connector
Affected Version<= 3.0.1
CVSS9.8Critical
CVECVE-2025-8570
View all BeyondCart Connector vulnerabilities

Vulnerability Overview

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.

Technical Analysis

REMEDIATION: Update to version 3.0.2, or a newer patched version --- IDENTIFIER: CWE-798 (Use of Hard-coded Credentials) The product contains hard-coded credentials, such as a password or cryptographic key.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C