Executive brief
LitExtension is a WordPress plugin that migrates e-commerce store data to WooCommerce. A missing security check allows attackers to trick a logged-in store administrator into clicking a malicious link, which replaces the plugin's authentication token with an attacker-controlled value. Once the token is compromised, an attacker can read and write files on the server, potentially leading to unauthorized access or code execution.
Technical details
The vulnerability is a Cross-Site Request Forgery (CSRF) affecting the LitExtension Store to WooCommerce Migration plugin through version 1.2.5. The plugin's administrative action to install or update the connector authentication token accepts a GET parameter without verifying a nonce, failing to validate that the request originated from the legitimate administrator. An attacker can craft a link (https://victim.example/wp-admin/admin.php?page=install-connector&token=ATTACKER_CHOSEN_TOKEN) that, when clicked by a logged-in administrator, overwrites the LECM_TOKEN in the connector bridge file. With control of the authentication token, the attacker can then access the public connector endpoint to perform file operations (read/write) via the file action parameter. The plugin creates the connector bridge file during the migration workflow; a fresh install is not vulnerable. The vulnerability is fixed in version 1.2.7.
Affected products
- LitExtension Store to WooCommerce Migration through 1.2.5
Timeline
- 2026-08-14: disclosed
- 2026-08-21: patched: Fix released in version 1.2.7