CVE-2026-76009 PUBLISHED

Next-Cart Store to WooCommerce Migration <= 3.9.8 - Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint

Assigner: Wordfence
Reserved: 18.08.2026 Published: 09.09.2026 Updated: 09.09.2026

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the NCWM_Kitconnect::run() function. This is due to the plugin registering the /wp-json/next_cart/v1/migration REST route with permission_callback set to __return_true and relying on a hardcoded fallback value of __token__ in get_option('nextcart_token', '__token__') when the nextcart_token option has not yet been written to the database. This makes it possible for unauthenticated attackers to bypass authentication to the migration endpoint by supplying the literal string __token__ as the token, gaining access to privileged handlers that pass attacker-controlled SQL directly to $wpdb->query() and $wpdb->get_results() — enabling arbitrary SQL execution including administrator account creation — and pass an attacker-controlled path to unlink(), enabling arbitrary file deletion and full site takeover. The hardcoded fallback is reachable whenever the nextcart_token option has not yet been populated, which occurs after WP-CLI, network, or programmatic plugin activation without a subsequent authenticated wp-admin visit, as token generation is deferred to admin_init via register_settings().

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor martinnguyen1990
Product Next-Cart Store to WooCommerce Migration
Versions Default: unaffected
  • affected from 0 to 3.9.8 (incl.)

Credits

  • Samuele Santonicola finder

References

Problem Types

  • CWE-287 Improper Authentication CWE