Loading market data...
← Back to CVE feed

CVE-2026-15046

MEDIUM CVSS 4.2 View on NVD ↗

Description

The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF).

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Published: Aug 21, 2026 12:16 UTC Modified: Aug 21, 2026 13:16 UTC