{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/store-to-woocommerce-migration--3.9.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:next-cart:store_to_woocommerce_migration:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-76009"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Store to WooCommerce Migration (\u003c= 3.9.8)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["Next-Cart"],"content_html":"\u003cp\u003eThe Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to an authentication bypass in all versions up to and including 3.9.8. The vulnerability exists within the \u003ccode\u003eNCWM_Kitconnect::run()\u003c/code\u003e function due to an insecurely configured REST API route (\u003ccode\u003e/wp-json/next_cart/v1/migration\u003c/code\u003e). The plugin registers this route with a \u003ccode\u003epermission_callback\u003c/code\u003e set to \u003ccode\u003e__return_true\u003c/code\u003e, meaning no authentication is required by default. Furthermore, the plugin utilizes a hardcoded fallback value of \u003ccode\u003e__token__\u003c/code\u003e via \u003ccode\u003eget_option('nextcart_token', '__token__')\u003c/code\u003e if the migration token has not been explicitly generated in the database.\u003c/p\u003e\n\u003cp\u003eThis hardcoded fallback is reachable when the plugin is activated via WP-CLI, network-wide, or programmatically without a subsequent \u003ccode\u003ewp-admin\u003c/code\u003e visit, as the legitimate token generation is deferred to the \u003ccode\u003eadmin_init\u003c/code\u003e hook. An unauthenticated attacker can supply the string \u003ccode\u003e__token__\u003c/code\u003e to the REST endpoint to bypass authentication. Once inside, the attacker can leverage privileged handlers to execute arbitrary SQL queries against the database (enabling admin account creation) and trigger arbitrary file deletion via \u003ccode\u003eunlink()\u003c/code\u003e, potentially resulting in a full site takeover.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify WordPress sites with the Next-Cart plugin activated via CLI or programmatic methods.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the REST API endpoint at \u003ccode\u003e/wp-json/next_cart/v1/migration\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker submits the literal string \u003ccode\u003e__token__\u003c/code\u003e in the request parameters to the endpoint.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to validate authentication due to the insecure \u003ccode\u003epermission_callback\u003c/code\u003e and the hardcoded fallback token.\u003c/li\u003e\n\u003cli\u003eAttacker sends malicious SQL payloads to the migration handler, which passes them to \u003ccode\u003e$wpdb-\u0026gt;query()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a new administrator user into the \u003ccode\u003ewp_users\u003c/code\u003e and \u003ccode\u003ewp_usermeta\u003c/code\u003e tables.\u003c/li\u003e\n\u003cli\u003eAttacker sends file system commands to the handler, which passes paths to \u003ccode\u003eunlink()\u003c/code\u003e for arbitrary file deletion.\u003c/li\u003e\n\u003cli\u003eAttacker completes site takeover by leveraging elevated privileges and persistence through newly created accounts.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-76009 allows unauthenticated remote attackers to gain full administrative control over the affected WordPress site. Impacts include unauthorized access to sensitive customer data, site defacement, the injection of malicious code into the database, and the potential for complete site compromise. Given the prevalence of WordPress installations and the nature of migration tools, a significant number of instances configured via non-interactive means are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Next-Cart Store to WooCommerce Migration plugin to a version beyond 3.9.8 immediately.\u003c/li\u003e\n\u003cli\u003eAudit the \u003ccode\u003ewp_users\u003c/code\u003e and \u003ccode\u003ewp_usermeta\u003c/code\u003e tables for unauthorized administrative accounts created post-deployment.\u003c/li\u003e\n\u003cli\u003eInspect web server access logs for requests directed at \u003ccode\u003e/wp-json/next_cart/v1/migration\u003c/code\u003e containing the \u003ccode\u003e__token__\u003c/code\u003e string.\u003c/li\u003e\n\u003cli\u003ePerform a security review of site plugins to ensure no other REST routes lack proper \u003ccode\u003epermission_callback\u003c/code\u003e validation.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-09T06:48:16Z","date_published":"2026-09-09T06:48:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-76009/","summary":"An authentication bypass vulnerability (CVE-2026-76009) in the Next-Cart Store to WooCommerce Migration WordPress plugin allows unauthenticated attackers to execute arbitrary SQL and delete files, leading to potential site takeover.","title":"Authentication Bypass in Next-Cart Store to WooCommerce Migration Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-76009/"}],"language":"en","title":"CraftedSignal Threat Feed - Store to WooCommerce Migration (\u003c= 3.9.8)","version":"https://jsonfeed.org/version/1.1"}