BeyondCart Connector <= 3.0.1 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation via determine_current_user Filter
2025-09-10 18:48
kr0dStrategic Overview
StatusPatched in 3.0.2
Affected PluginBeyondCart Connector
Affected Version
<= 3.0.1CVSS9.8Critical
CVE
CVE-2025-8570Vulnerability Overview
The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.
Technical Analysis
REMEDIATION: Update to version 3.0.2, or a newer patched version --- IDENTIFIER: CWE-798 (Use of Hard-coded Credentials) The product contains hard-coded credentials, such as a password or cryptographic key.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C