LitExtension Blog
  • Ecommerce Platforms
    • Shopify
    • WooCommerce
    • Magento (Adobe Commerce)
    • Wix
    • Other Platforms
  • eCommerce Migration
    • Shopify Migration
    • WooCommerce Migration
    • Magento Migration
    • Other Migrations
  • Store Growth
  • LitExtension
    • LitExtension Updates
    • Case Study
No Result
View All Result
VISIT LITEXTENSION
LitExtension Blog
  • Ecommerce Platforms
    • Shopify
    • WooCommerce
    • Magento (Adobe Commerce)
    • Wix
    • Other Platforms
  • eCommerce Migration
    • Shopify Migration
    • WooCommerce Migration
    • Magento Migration
    • Other Migrations
  • Store Growth
  • LitExtension
    • LitExtension Updates
    • Case Study
No Result
View All Result
VISIT LITEXTENSION
LitExtension Blog
No Result
View All Result

Security Advisory: Connector vulnerabilities in the LitExtension WooCommerce Migration plugin

by jade
Sep, 2026
in Ecommerce News, Shopping Cart Migration Guides

Affected versions: 1.2.5 and earlier ·
Fixed in: 1.2.6 and 1.2.7 ·
CVE: CVE-2026-15046 ·
Severity: Medium (CVSS 4.2)

Summary

A security researcher reported a vulnerability in the way our WordPress migration plugin installed and authenticated its migration connector. We released fixes in versions 1.2.6 and 1.2.7, and both are available now through the WordPress plugin directory.

If you are running version 1.2.5 or earlier, update immediately. If you have finished your migration, we recommend deleting the plugin entirely.

What the issue was

The plugin’s connector is a small bridge file created during a migration so that data can be transferred into your store. Two problems existed in how it worked:

Missing CSRF protection. The administrative action that installed or updated the connector’s authentication token read that token from a URL parameter and did not verify a WordPress nonce. An attacker could craft a link that, if opened by a logged-in administrator, would overwrite the connector token with a value the attacker chose. The attacker did not need credentials for your site — only for an administrator to click the link while logged in.

An over-permissive connector. The connector authorised requests using that token alone, and had broader capabilities than a migration tool requires. Combined with the first issue, a researcher demonstrated that a controlled token could be used to write and execute code on the site.

We want to state this plainly: this was not a low-impact issue for sites that met the conditions below. We have treated it accordingly.

Who was affected

The connector bridge file only exists after a migration has been set up. It is not present on a fresh install. If you installed the plugin but never started a migration, this issue could not be triggered on your site.

Sites running 1.2.5 or earlier with a connector installed were the ones at risk.

What we fixed

In 1.2.6:

  • Installing, reinstalling and removing the connector now require administrator capability and a WordPress nonce, so they cannot be triggered by a cross-site request.
  • The connector token is generated on your site with a cryptographically secure random generator, and is never read from a URL parameter.
  • The connector is no longer downloaded from a remote server; it is a generated bridge running code shipped and reviewed with the plugin.
  • The connector can no longer read, write or move files outside the WordPress uploads folder, and can never write a file the web server would execute.
  • Database manager, phpinfo, opcache and free-form SQL console actions were removed entirely.
  • Any connector installed by 1.2.5 or earlier is removed on upgrade and its token revoked.
  • Added a REST route so migrations can be set up using WordPress Application Passwords.

In 1.2.7: further restrictions on the connector’s file copy action and directory listings.

What you should do

  1. Update to 1.2.7. Upgrading automatically removes any old connector and revokes its token.
  2. If your migration is complete, delete the plugin. It is a migration tool and does not need to stay installed. This removes the connector endpoint entirely.
  3. If you ran 1.2.5 or earlier with a connector installed, review your site for unexpected files (particularly PHP files with recent modification dates), unfamiliar administrator accounts, and unusual scheduled tasks. Reviewing your access logs for requests to le_connector/connector.php is a good starting point.
  4. If you find anything unexpected, contact us at [security email]. We will help you investigate at no cost.

Has any data been affected?

We have no evidence that this vulnerability was exploited against any site. It was reported through responsible disclosure, not discovered through an incident.

We want to be accurate rather than simply reassuring. Exploitation would leave traces on the affected WordPress site, not on LitExtension’s systems, so we cannot verify the state of every installation on our users’ behalf — which is why we are asking site owners to perform the checks above. Our own infrastructure was not affected, and we do not retain migration data or store credentials after a migration completes.

A note on vulnerability databases

Some vulnerability scanners currently list the affected range as “1.2.7 and earlier”. This is inaccurate — the CSRF issue was fixed in 1.2.6. We have contacted the relevant databases to correct the record. Sites running 1.2.7 may see a false positive until this is updated.

Acknowledgement

We thank marim00 for reporting this responsibly, and for the detail provided in the report. Our changelog for 1.2.6 credits this disclosure.

Reporting security issues

Please email [email protected]. We aim to acknowledge reports within 1 business day and will not pursue legal action against researchers acting in good faith.

Previous Post

Joomla Update Guide 2026: How to Update Joomla for Beginners

jade

jade

Free Migration Resources
Table of Contents
  1. Summary
  2. What the issue was
  3. Who was affected
  4. What we fixed
  5. What you should do
  6. Has any data been affected?
  7. A note on vulnerability databases
  8. Acknowledgement
  9. Reporting security issues

Popular eCommerce Migration

  1. Shopify Migration
  2. WooCommerce Migration
  3. Magento Migration
  4. BigCommerce Migration
  5. PrestaShop Migration

Best Ecommerce Platforms

  1. Shopify Review
  2. WooCommerce Review
  3. Wix Ecommerce Review
  4. BigCommerce Review
  5. Best Ecommerce Platforms

 

Popular Migration Pairs

  • Wix to Shopify
  • Magento to Shopify
  • BigCommerce to Shopify
  • WooCommerce to Shopify
  • Shopify to WooCommerce

Company

  • About LitExtension
  • Success Stories
  • Sitemap
  • Disclosures
  • Our Author
  • Contact Us

DMCA.com Protection Status

  • All the Basics to Build eCommerce Website
  • Disclosures
  • LitExtension Authors
  • LitExtension Blog – Shopping Cart Migration Expert & eCommerce News
  • LitExtension Blog Sitemap
  • LitExtension Methodology

© 2011 - 2024 LitExtension.com All Rights Reserved.

No Result
View All Result
  • Ecommerce Platforms
    • Shopify
    • WooCommerce
    • Magento (Adobe Commerce)
    • Wix
    • Other Platforms
  • eCommerce Migration
    • Shopify Migration
    • WooCommerce Migration
    • Magento Migration
    • Other Migrations
  • Store Growth
  • Ecommerce News
    • News & Events
    • Case Studies
VISIT LITEXTENSION

© 2011 - 2024 LitExtension.com All Rights Reserved.