Privilege Escalation Vulnerability in BeyondCart Connector for WordPress
CVE-2025-8570
9.8CRITICAL
What is CVE-2025-8570?
The BeyondCart Connector plugin for WordPress contains a vulnerability that allows unauthenticated users to exploit improper management of JSON Web Tokens (JWT). Specifically, the flaw lies in the inadequate authorization handling within the determine_current_user filter, present in versions 1.4.2 to 2.1.0. This vulnerability enables attackers to craft valid tokens, potentially impersonating any user, thereby affecting the security and integrity of user accounts on affected WordPress sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BeyondCart Connector * <= 2.1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kenneth Dunn