Description
The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 2.1.0. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.
Problem types
CWE-798 Use of Hard-coded Credentials
Product status
* (semver)
Timeline
| 2025-09-10: | Disclosed |
Credits
Kenneth Dunn
References
www.wordfence.com/...-1c6a-4556-b219-893563a27a69?source=cve
wordpress.org/plugins/beyondcart/