Description
WordPress Plugin WooCommerce Payments-Fully Integrated Solution Built and Supported by Woo is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently impersonate arbitrary users and perform some actions as the impersonated user, which can lead to site takeover. WordPress Plugin WooCommerce Payments-Fully Integrated Solution Built and Supported by Woo versions 4.8.0 - 5.6.1 are vulnerable.
Remediation
Update to plugin versions 4.8.2, 4.9.1, 5.0.4, 5.1.3, 5.2.2, 5.3.1, 5.4.1, 5.5.2, 5.6.2 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:0F78A245-866C-462E-BD23-43DFADB57072
https://plugins.svn.wordpress.org/woocommerce-payments/trunk/readme.txt
Related Vulnerabilities
OpenSSL Out-of-bounds Write Vulnerability (CVE-2022-3602)
WordPress Plugin Events Manager Extended 'admin.php' SQL Injection (3.1.2)
Oracle Application Server CVE-2009-1976 Vulnerability (CVE-2009-1976)
Oracle Database Server CVE-2014-6538 Vulnerability (CVE-2014-6538)
WordPress Plugin Sports Rankings and Lists Cross-Site Scripting (3.5)