PT-2026-45711 · Ntbyk · Putler Connector For Woocommerce

Muhan Luo

·

Published

2026-06-02

·

Updated

2026-06-02

·

CVE-2026-9234

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin post settings save woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and on the wp ajax downloadJTLLogs and wp ajax clearJTLLogs AJAX actions (handled by the global downloadJTLLogs() and clearJTLLogs() functions). This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary plugin settings, download a ZIP archive of the connector's developer log files, and delete those log files.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-9234

Affected Products

Putler Connector For Woocommerce