PT-2025-37134 · WordPress · Beyondcart Connector

Kenneth Dunn

·

Published

2025-09-11

·

Updated

2025-09-16

·

CVE-2025-8570

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BeyondCart Connector plugin for WordPress versions 1.4.2 through 2.1.0
Description The BeyondCart Connector plugin for WordPress is susceptible to privilege escalation due to improper JWT (JSON Web Token) secret management and authorization within the determine current user filter. This allows unauthenticated attackers to create valid tokens and impersonate any user.
Recommendations Update BeyondCart Connector plugin to a version later than 2.1.0.

Fix

LPE

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8570

Affected Products

Beyondcart Connector