{"id":94393,"date":"2026-08-29T13:51:32","date_gmt":"2026-08-29T17:51:32","guid":{"rendered":"https:\/\/litextension.com\/blog\/?p=94393"},"modified":"2026-09-04T14:06:29","modified_gmt":"2026-09-04T18:06:29","slug":"security-advisory","status":"publish","type":"post","link":"https:\/\/litextension.com\/blog\/security-advisory\/","title":{"rendered":"Security Advisory: Connector vulnerabilities in the LitExtension WooCommerce Migration plugin"},"content":{"rendered":"<p><strong>Affected versions:<\/strong> 1.2.5 and earlier \u00b7<br \/>\n<strong>Fixed in:<\/strong> 1.2.6 and 1.2.7 \u00b7<br \/>\n<strong>CVE:<\/strong> CVE-2026-15046 \u00b7<br \/>\n<strong>Severity:<\/strong> Medium (CVSS 4.2)<\/p>\n<h2>Summary<\/h2>\n<p>A security researcher reported a vulnerability in the way our WordPress migration plugin installed and authenticated its migration connector. We released fixes in versions 1.2.6 and 1.2.7, and both are available now through the WordPress plugin directory.<\/p>\n<p>If you are running version 1.2.5 or earlier, <strong>update immediately<\/strong>. If you have finished your migration, we recommend deleting the plugin entirely.<\/p>\n<h2>What the issue was<\/h2>\n<p>The plugin&#8217;s connector is a small bridge file created during a migration so that data can be transferred into your store. Two problems existed in how it worked:<\/p>\n<p><strong>Missing CSRF protection.<\/strong> The administrative action that installed or updated the connector&#8217;s authentication token read that token from a URL parameter and did not verify a WordPress nonce. An attacker could craft a link that, if opened by a logged-in administrator, would overwrite the connector token with a value the attacker chose. The attacker did not need credentials for your site \u2014 only for an administrator to click the link while logged in.<\/p>\n<p><strong>An over-permissive connector.<\/strong> The connector authorised requests using that token alone, and had broader capabilities than a migration tool requires. Combined with the first issue, a researcher demonstrated that a controlled token could be used to write and execute code on the site.<\/p>\n<p>We want to state this plainly: this was not a low-impact issue for sites that met the conditions below. We have treated it accordingly.<\/p>\n<h2>Who was affected<\/h2>\n<p>The connector bridge file only exists <strong>after a migration has been set up<\/strong>. It is not present on a fresh install. If you installed the plugin but never started a migration, this issue could not be triggered on your site.<\/p>\n<p>Sites running <strong>1.2.5 or earlier with a connector installed<\/strong> were the ones at risk.<\/p>\n<h2>What we fixed<\/h2>\n<p><strong>In 1.2.6:<\/strong><\/p>\n<ul>\n<li>Installing, reinstalling and removing the connector now require administrator capability <em>and<\/em> a WordPress nonce, so they cannot be triggered by a cross-site request.<\/li>\n<li>The connector token is generated on your site with a cryptographically secure random generator, and is never read from a URL parameter.<\/li>\n<li>The connector is no longer downloaded from a remote server; it is a generated bridge running code shipped and reviewed with the plugin.<\/li>\n<li>The connector can no longer read, write or move files outside the WordPress uploads folder, and can never write a file the web server would execute.<\/li>\n<li>Database manager, phpinfo, opcache and free-form SQL console actions were removed entirely.<\/li>\n<li><strong>Any connector installed by 1.2.5 or earlier is removed on upgrade and its token revoked.<\/strong><\/li>\n<li>Added a REST route so migrations can be set up using WordPress Application Passwords.<\/li>\n<\/ul>\n<p><strong>In 1.2.7:<\/strong> further restrictions on the connector&#8217;s file copy action and directory listings.<\/p>\n<h2>What you should do<\/h2>\n<ol>\n<li><strong>Update to 1.2.7.<\/strong> Upgrading automatically removes any old connector and revokes its token.<\/li>\n<li><strong>If your migration is complete, delete the plugin.<\/strong> It is a migration tool and does not need to stay installed. This removes the connector endpoint entirely.<\/li>\n<li><strong>If you ran 1.2.5 or earlier with a connector installed,<\/strong> review your site for unexpected files (particularly PHP files with recent modification dates), unfamiliar administrator accounts, and unusual scheduled tasks. Reviewing your access logs for requests to <code>le_connector\/connector.php<\/code> is a good starting point.<\/li>\n<li><strong>If you find anything unexpected,<\/strong> contact us at [security email]. We will help you investigate at no cost.<\/li>\n<\/ol>\n<h2>Has any data been affected?<\/h2>\n<p>We have no evidence that this vulnerability was exploited against any site. It was reported through responsible disclosure, not discovered through an incident.<\/p>\n<p>We want to be accurate rather than simply reassuring. Exploitation would leave traces on the affected WordPress site, not on LitExtension&#8217;s systems, so we cannot verify the state of every installation on our users&#8217; behalf \u2014 which is why we are asking site owners to perform the checks above. Our own infrastructure was not affected, and we do not retain migration data or store credentials after a migration completes.<\/p>\n<h2>A note on vulnerability databases<\/h2>\n<p>Some vulnerability scanners currently list the affected range as &#8220;1.2.7 and earlier&#8221;. This is inaccurate \u2014 the CSRF issue was fixed in 1.2.6. We have contacted the relevant databases to correct the record. Sites running 1.2.7 may see a false positive until this is updated.<\/p>\n<h2>Acknowledgement<\/h2>\n<p>We thank <strong>marim00<\/strong> for reporting this responsibly, and for the detail provided in the report. Our changelog for 1.2.6 credits this disclosure.<\/p>\n<h2>Reporting security issues<\/h2>\n<p>Please email <a href=\"mailto:contact@litextension.com\">contact@litextension.com<\/a>. We aim to acknowledge reports within 1 business day and will not pursue legal action against researchers acting in good faith.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Affected versions: 1.2.5 and earlier \u00b7 Fixed in: 1.2.6 and 1.2.7 \u00b7 CVE: CVE-2026-15046 \u00b7 Severity: Medium (CVSS 4.2) Summary A security researcher reported a vulnerability in the way our WordPress migration plugin installed and authenticated its migration connector. We released fixes in versions 1.2.6 and 1.2.7, and both are available now through the WordPress [&hellip;]<\/p>\n","protected":false},"author":80,"featured_media":94401,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","jnews-multi-image_gallery":[],"jnews_single_post":{"format":"standard"},"jnews_primary_category":[],"footnotes":""},"categories":[16640,1],"tags":[],"table_tags":[],"class_list":["post-94393","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ecommerce-news","category-shopping-cart-migration-guuide"],"uagb_featured_image_src":{"full":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1.png",1500,1072,false],"thumbnail":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-150x150.png",150,150,true],"medium":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-300x214.png",300,214,true],"medium_large":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-768x549.png",768,549,true],"large":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-1024x732.png",1024,732,true],"1536x1536":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1.png",1500,1072,false],"2048x2048":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1.png",1500,1072,false],"jnews-360x180":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-360x180.png",360,180,true],"jnews-750x375":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-750x375.png",750,375,true],"jnews-1140x570":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-1140x570.png",1140,570,true],"jnews-120x86":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-120x86.png",120,86,true],"jnews-350x250":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-350x250.png",350,250,true],"jnews-750x536":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-750x536.png",750,536,true],"jnews-1140x815":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-1140x815.png",1140,815,true],"jnews-360x504":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-360x504.png",360,504,true],"jnews-75x75":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-75x75.png",75,75,true],"jnews-350x350":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-350x350.png",350,350,true],"jnews-featured-750":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-750x536.png",750,536,true],"jnews-featured-1140":["https:\/\/litextension.com\/blog\/wp-content\/uploads\/2026\/08\/Security-Advisory-1-1140x815.png",1140,815,true]},"uagb_author_info":{"display_name":"jade","author_link":"https:\/\/litextension.com\/blog\/author\/jade\/"},"uagb_comment_info":0,"uagb_excerpt":"Affected versions: 1.2.5 and earlier \u00b7 Fixed in: 1.2.6 and 1.2.7 \u00b7 CVE: CVE-2026-15046 \u00b7 Severity: Medium (CVSS 4.2) Summary A security researcher reported a vulnerability in the way our WordPress migration plugin installed and authenticated its migration connector. We released fixes in versions 1.2.6 and 1.2.7, and both are available now through the WordPress&hellip;","_links":{"self":[{"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/posts\/94393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/users\/80"}],"replies":[{"embeddable":true,"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/comments?post=94393"}],"version-history":[{"count":2,"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/posts\/94393\/revisions"}],"predecessor-version":[{"id":94402,"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/posts\/94393\/revisions\/94402"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/media\/94401"}],"wp:attachment":[{"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/media?parent=94393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/categories?post=94393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/tags?post=94393"},{"taxonomy":"table_tags","embeddable":true,"href":"https:\/\/litextension.com\/blog\/wp-json\/wp\/v2\/table_tags?post=94393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}