Files
CVEs-PoC/2025/CVE-2025-8570.md
T
2025-09-29 21:09:30 +02:00

931 B
Raw Blame History

CVE-2025-8570

Description

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 2.1.0. This makes it possible for unauthenticated attackers to craft valid tokens and assume any users identity.

POC

Reference

No PoCs from references.

Github