Junglewise Threat Intelligence

CVE-2026-9234: JTL-Software JTL-Connector for WooCommerce missing authorization

CVE-2026-9234 · Severity: medium · CVSS 4.3 · Published 2026-06-02

Executive brief

The JTL-Connector for WooCommerce plugin for WordPress, which synchronizes data between WooCommerce stores and JTL-Wawi ERP systems, contains a security flaw. This vulnerability allows any logged-in user, even those with low-level permissions like subscribers, to change plugin settings or access and delete developer log files. This could lead to unauthorized configuration changes or the loss of diagnostic data.

Technical details

The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to missing authorization (CWE-862) due to a lack of capability checks and nonce verification in several functions. Specifically, the 'admin_post_settings_save_woo-jtl-connector' action (handled by JtlConnectorAdmin::save()) and the AJAX actions 'wp_ajax_downloadJTLLogs' and 'wp_ajax_clearJTLLogs' are affected. An authenticated attacker with Subscriber-level permissions or higher can exploit these endpoints via network requests to modify arbitrary plugin settings, download a ZIP archive of developer logs, or delete log files. The vulnerability exists in all versions up to and including 2.4.1.

Affected products

  • JTL-Software-GmbH JTL-Connector for WooCommerce up to, and including, 2.4.1

Timeline

  • 2026-06-02: disclosed: Vulnerability published to NVD
  • 2026-06-02: advisory: Wordfence advisory published

References