CVE-2026-15046EPSS p1.6%
CVE-2026-15046CVE-2026-15046
Description
The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF).
Scoring
| CVSS | 4.2 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
| EPSS | 0.12% probability of exploitation · percentile 1.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-26 |