Junglewise Threat Intelligence

CVE-2026-15046: LitExtension Store to WooCommerce Migration CSRF connector token takeover

CVE-2026-15046 · Severity: medium · CVSS 4.2 · Published 2026-08-21

Executive brief

LitExtension is a WordPress plugin that migrates e-commerce store data to WooCommerce. A missing security check allows attackers to trick a logged-in store administrator into clicking a malicious link, which replaces the plugin's authentication token with an attacker-controlled value. Once the token is compromised, an attacker can read and write files on the server, potentially leading to unauthorized access or code execution.

Technical details

The vulnerability is a Cross-Site Request Forgery (CSRF) affecting the LitExtension Store to WooCommerce Migration plugin through version 1.2.5. The plugin's administrative action to install or update the connector authentication token accepts a GET parameter without verifying a nonce, failing to validate that the request originated from the legitimate administrator. An attacker can craft a link (https://victim.example/wp-admin/admin.php?page=install-connector&token=ATTACKER_CHOSEN_TOKEN) that, when clicked by a logged-in administrator, overwrites the LECM_TOKEN in the connector bridge file. With control of the authentication token, the attacker can then access the public connector endpoint to perform file operations (read/write) via the file action parameter. The plugin creates the connector bridge file during the migration workflow; a fresh install is not vulnerable. The vulnerability is fixed in version 1.2.7.

Affected products

  • LitExtension Store to WooCommerce Migration through 1.2.5

Timeline

  • 2026-08-14: disclosed
  • 2026-08-21: patched: Fix released in version 1.2.7

References