The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 2.1.0. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.
                
            References
                    Configurations
                    No configuration.
History
                    11 Sep 2025, 08:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-09-11 08:15
Updated : 2025-09-11 17:14
NVD link : CVE-2025-8570
Mitre link : CVE-2025-8570
CVE.ORG link : CVE-2025-8570
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-798
                        
            Use of Hard-coded Credentials
