Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3j9m-4q8w-cqcp

Опубликовано: 11 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 2.1.0. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 2.1.0. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.

EPSS

Процентиль: 14%
0.00046
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
5 месяцев назад

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 2.1.0. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.

EPSS

Процентиль: 14%
0.00046
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798