Impact
The Next-Cart Store to WooCommerce Migration plugin contains an authentication bypass flaw that allows unauthenticated users to access a REST endpoint with no permission checks. By sending the literal string '__token__' as the token, an attacker can trigger privileged handlers that directly inject arbitrary SQL into the database and call unlink() on arbitrary paths, resulting in full site takeover. The vulnerability can be used to create administrator accounts, delete files, and gain remote code execution.
Affected Systems
The flaw affects all editions of the Next-Cart Store to WooCommerce Migration WordPress plugin from its initial release through version 3.9.8. The affected product is developed by martinnguyen1990 and the vulnerable REST route is exposed under /wp-json/next_cart/v1/migration in the WordPress installation.
Risk and Exploitability
With a CVSS score of 8.1 this issue is considered high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, yet the attack path is straightforward: an unauthenticated attacker can reach the endpoint and supply the default token. The capability to execute arbitrary SQL queries and delete files makes exploitation of this flaw likely to lead to full compromise of the affected WordPress site.
OpenCVE Enrichment