Description
WordPress Plugin WooCommerce Payments-Fully Integrated Solution Built and Supported by Woo is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently impersonate arbitrary users and perform some actions as the impersonated user, which can lead to site takeover. WordPress Plugin WooCommerce Payments-Fully Integrated Solution Built and Supported by Woo versions 4.8.0 - 5.6.1 are vulnerable.
Remediation
Update to plugin versions 4.8.2, 4.9.1, 5.0.4, 5.1.3, 5.2.2, 5.3.1, 5.4.1, 5.5.2, 5.6.2 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:0F78A245-866C-462E-BD23-43DFADB57072
https://plugins.svn.wordpress.org/woocommerce-payments/trunk/readme.txt