Description
WordPress Plugin WooCommerce Payments-Fully Integrated Solution Built and Supported by Woo is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently impersonate arbitrary users and perform some actions as the impersonated user, which can lead to site takeover. WordPress Plugin WooCommerce Payments-Fully Integrated Solution Built and Supported by Woo versions 4.8.0 - 5.6.1 are vulnerable.
Remediation
Update to plugin versions 4.8.2, 4.9.1, 5.0.4, 5.1.3, 5.2.2, 5.3.1, 5.4.1, 5.5.2, 5.6.2 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:0F78A245-866C-462E-BD23-43DFADB57072
https://plugins.svn.wordpress.org/woocommerce-payments/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WordPress Geo-CF Geo Cross-Site Scripting (7.13.11)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-6626)
WordPress Plugin Great Quotes Cross-Site Scripting (1.0.0)
PostgreSQL Improper Certificate Validation Vulnerability (CVE-2021-43767)
WordPress Plugin WordPress Leads Cross-Site Scripting (1.6.2)