PoC Index

CVE-2026-15046

MEDIUM 4.2EPSS 0.1%

The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF).

CVSS v3.1
4.2 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS
0.09% chance of exploitation in the next 30 days, 1th percentile
Published
2026-08-21

Proof-of-concept exploits (1)

References

Related