Description
The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to `__return_true` and relying on a hardcoded fallback value of `__token__` in `get_option('nextcart_token', '__token__')` when the `nextcart_token` option has not yet been written to the database. This makes it possible for unauthenticated attackers to bypass authentication to the migration endpoint by supplying the literal string `__token__` as the token, gaining access to privileged handlers that pass attacker-controlled SQL directly to `$wpdb->query()` and `$wpdb->get_results()` — enabling arbitrary SQL execution including administrator account creation — and pass an attacker-controlled path to `unlink()`, enabling arbitrary file deletion and full site takeover. The hardcoded fallback is reachable whenever the `nextcart_token` option has not yet been populated, which occurs after WP-CLI, network, or programmatic plugin activation without a subsequent authenticated `wp-admin` visit, as token generation is deferred to `admin_init` via `register_settings()`.
Published: 2026-09-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Next-Cart Store to WooCommerce Migration plugin contains an authentication bypass flaw that allows unauthenticated users to access a REST endpoint with no permission checks. By sending the literal string '__token__' as the token, an attacker can trigger privileged handlers that directly inject arbitrary SQL into the database and call unlink() on arbitrary paths, resulting in full site takeover. The vulnerability can be used to create administrator accounts, delete files, and gain remote code execution.

Affected Systems

The flaw affects all editions of the Next-Cart Store to WooCommerce Migration WordPress plugin from its initial release through version 3.9.8. The affected product is developed by martinnguyen1990 and the vulnerable REST route is exposed under /wp-json/next_cart/v1/migration in the WordPress installation.

Risk and Exploitability

With a CVSS score of 8.1 this issue is considered high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, yet the attack path is straightforward: an unauthenticated attacker can reach the endpoint and supply the default token. The capability to execute arbitrary SQL queries and delete files makes exploitation of this flaw likely to lead to full compromise of the affected WordPress site.

Generated by OpenCVE AI on September 9, 2026 at 10:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Next-Cart Store to WooCommerce Migration plugin to the latest version (3.9.9 or newer) to remove the hardcoded token fallback
  • If an upgrade cannot be performed immediately, deactivate or uninstall the plugin to eliminate the vulnerable REST endpoint
  • After applying a fix, delete any existing 'nextcart_token' option entries from the database to ensure the default token is not used

Generated by OpenCVE AI on September 9, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Martinnguyen1990
Martinnguyen1990 next-cart Store To Woocommerce Migration
Wordpress
Wordpress wordpress
Vendors & Products Martinnguyen1990
Martinnguyen1990 next-cart Store To Woocommerce Migration
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to `__return_true` and relying on a hardcoded fallback value of `__token__` in `get_option('nextcart_token', '__token__')` when the `nextcart_token` option has not yet been written to the database. This makes it possible for unauthenticated attackers to bypass authentication to the migration endpoint by supplying the literal string `__token__` as the token, gaining access to privileged handlers that pass attacker-controlled SQL directly to `$wpdb->query()` and `$wpdb->get_results()` — enabling arbitrary SQL execution including administrator account creation — and pass an attacker-controlled path to `unlink()`, enabling arbitrary file deletion and full site takeover. The hardcoded fallback is reachable whenever the `nextcart_token` option has not yet been populated, which occurs after WP-CLI, network, or programmatic plugin activation without a subsequent authenticated `wp-admin` visit, as token generation is deferred to `admin_init` via `register_settings()`.
Title Next-Cart Store to WooCommerce Migration <= 3.9.8 - Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Martinnguyen1990 Next-cart Store To Woocommerce Migration
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T14:01:28.611Z

Reserved: 2026-08-18T18:55:14.714Z

Link: CVE-2026-76009

cve-icon Vulnrichment

Updated: 2026-09-09T14:01:25.034Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:16.497

Modified: 2026-09-09T15:33:34.467

Link: CVE-2026-76009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:07Z

Weaknesses