SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15046

MEDIUM · CVSS 4.2 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The LitExtension WordPress plugin versions up to 1.2.5 are vulnerable to a cross-site request forgery (CSRF) attack, which allows an attacker to overwrite the store-migration connector's authentication token without proper nonce verification. This could lead to unauthorized access and control over the migration connector by exploiting a logged-in administrator's session through a malicious link. WordPress site administrators using this plugin should prioritize updating to mitigate potential security risks.

CVE
CVE-2026-15046
Severity
MEDIUM
CVSS
4.2
EPSS
0.09%
WordPress

Original NVD Description

The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF).