CVE-2025-8570
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-11

Last updated on: 2026-04-08

Assigner: Wordfence

Description
The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-11
Last Modified
2026-04-08
Generated
2026-06-16
AI Q&A
2025-09-11
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
wordpress wordpress *
beyondcart beyondcart_connector *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The BeyondCart Connector plugin for WordPress has a vulnerability that allows privilege escalation. This happens because the plugin improperly manages the JWT secret and authorization in the determine_current_user filter. As a result, unauthenticated attackers can create valid tokens and impersonate any user on the site.

Impact Analysis

This vulnerability can have a severe impact as attackers can gain unauthorized access by assuming any user's identity without authentication. This can lead to full compromise of the WordPress site, including data theft, unauthorized actions, and complete loss of control over the site.

Mitigation Strategies

Immediate steps include disabling or uninstalling the BeyondCart Connector plugin if it is installed, especially versions 1.4.2 through 2.1.0, since the plugin has been temporarily closed pending a full review. Additionally, ensure that your WordPress installation and plugins are updated once a secure version of BeyondCart Connector is released. Monitor official channels for updates and avoid using the plugin until a fix is available. [1]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-8570. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart