Description
WordPress Plugin WooCommerce Customers Manager is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin WooCommerce Customers Manager version 26.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 26.5 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:126143E0-B0CC-4517-862E-3AC557DB744F
https://codecanyon.net/item/woocommerce-customers-manager/10965432#item-description__change-log
Related Vulnerabilities
WordPress Plugin Bilingual Linker Cross-Site Scripting (2.1.1)
WebLogic Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2019-17195)
WordPress Plugin Advanced Contact form 7 DB SQL Injection (1.6.0)
WordPress Plugin WordPoints Multiple Vulnerabilities (1.10.2)
Oracle Database Server CVE-2009-1994 Vulnerability (CVE-2009-1994)