Security Advisory

CVE-2026-15046

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-21 11:40:39
Last updated 2026-08-21 12:48:33
Assigner WPScan
CVSS score 4.2
State PUBLISHED

Description

The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF).