CyberRota Analysis
AI-GeneratedThe LitExtension WordPress plugin versions up to 1.2.5 are vulnerable to a cross-site request forgery (CSRF) attack, which allows an attacker to overwrite the store-migration connector's authentication token without proper nonce verification. This could lead to unauthorized access and control over the migration connector by exploiting a logged-in administrator's session through a malicious link. WordPress site administrators using this plugin should prioritize updating to mitigate potential security risks.
Original NVD Description
The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF).