Access violation vulnerability in Cart2Cart: Magento to WooCommerce Migration 2.0.0

The Cart2Cart: Magento to WooCommerce Migration plugin for WordPress has a security issue in versions up to 2.0.0 which makes it possible for someone with a subscriber-level account or higher to modify data without permission. This happens because there is no capability check on the setToken AJAX function which allows the user to set an access token that enables them to use the bridge2cart feature.

Detected in:

Cart2Cart: Magento to WooCommerce Migration open vulnerable versions: >= * <= 2.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.