Description
WordPress Plugin WooCommerce Anti-Fraud is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently reset all orders' statuses to processing. WordPress Plugin WooCommerce Anti-Fraud version 3.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3 or latest
References
https://twitter.com/BrianHenryIE/status/1330300510331613185
https://dzv365zjfbd8v.cloudfront.net/changelogs/woocommerce-anti-fraud/changelog.txt
Related Vulnerabilities
WordPress 4.4.x PHP Object Injection (4.4 - 4.4.24)
WordPress Ultimate Member Plugin Other Vulnerability (CVE-2022-3383)
WordPress Plugin Catch Breadcrumb Cross-Site Scripting (1.5.4)
WordPress Plugin How to Create an App for Android iPhone Easytouch Arbitrary File Upload (3.0)
WordPress Plugin SEO SearchTerms Tagging 2 Multiple Vulnerabilities (1.535)