CVE-2025-8570
Published
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT
Description
The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.
<p>Turn One-time Shoppers into Reccuring Revenue</p>
<p>Connector to BeyondCart – SaaS product that transform your eCommerce to a mobile app instantly and build customers for life! Analyze their behavior and drive repeat sales with targeted push notifications.</p>
<h3>Build customersfor life</h3>
<p>Make users stick around and drive repeat purchases with a Mobile Shopping App and Customer Engagement Platform</p>
<h3>Boost your business with a Mobile Shopping App</h3>
<p>Engage shoppers where they’re most likely to convert – their phone. Offer a personalized shopping experience that keep cusomers ready to buy.</p>
<p>Offer users an ultimate experience that help them find easily what they want wherever they are.<br />
Your mobile shopping app is full with features that will retain your customers and will help you build community for a lifetime</p>
<h3>Drive sustainable growth with Customer Engagment Platform</h3>
<p>Use our customer engagement platform to ultimate your targeting strategy and drive repeat sales with the power of push notifications.</p>
<p>While users interact with your mobile shopping app our customer engagement platform records their in-app behaviour.<br />
The details of every session logged are used to form the isights you need to drive sales</p>
<h3>Push notifications center</h3>
<p>Drive sales and repeat purchases by sending data-driven push notifications based on customer in-app behaviour, preferences and purchase patterns.</p>
<h3>Beyond Cart is super easy to integrate with your online store</h3>
<p>✔ <strong>Our team of experts converts your store to a fully branded Android and iOS Shopping App</strong><br />
✔ <strong>We handle the app submission and publishing process, so there is nothing new to figure out</strong><br />
✔ <strong>After your app becomes available in the app stores we will support you to ensure the success of your project</strong></p>
<h3>Our website:</h3>
<p>Any questions? Visit our website <a href="https://beyondcart.com/?utm_source=wordpress.org" rel="nofollow ugc">beyondcart.com</a></p>
<h3>External Services</h3>
<p>This plugin relies on 3rd party services for its ‘Sign in with Apple’, ‘Login with Google’, and ‘Login with Facebook’ features:</p>
<h4>Sign in with Apple</h4>
<ul>
<li>Apple’s authentication servers are contacted to fetch public keys for verifying JSON Web Tokens (JWT) when users sign in with their Apple IDs.</li>
<li>Apple’s authentication server URL: https://appleid.apple.com/auth/keys</li>
<li>Apple’s Privacy Policy: https://www.apple.com/legal/privacy/en-ww/</li>
<li>Apple’s Terms of Use: https://www.apple.com/legal/internet-services/terms/site.html</li>
</ul>
<h4>Login with Google</h4>
<ul>
<li>Google’s authentication servers are contacted when users sign in with their Google accounts.</li>
<li>Google API Console: https://console.developers.google.com/</li>
<li>Google’s Privacy Policy: https://policies.google.com/privacy</li>
<li>Google’s Terms of Service: https://policies.google.com/terms</li>
</ul>
<h4>Login with Facebook</h4>
<ul>
<li>Facebook’s authentication servers are contacted when users sign in with their Facebook accounts.</li>
<li>Facebook for Developers: https://developers.facebook.com/</li>
<li>Facebook’s Data Policy: https://www.facebook.com/policy.php</li>
<li>Facebook’s Terms of Service: https://www.facebook.com/terms.php</li>
</ul>