Description
WordPress Plugin Warranties and Returns for WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently take over the website and its database. WordPress Plugin Warranties and Returns for WooCommerce version 5.2.1 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 5.3.0 or latest
References
Related Vulnerabilities
WordPress Plugin WORDPRESS VIDEO GALLERY SQL Injection (2.7)
WordPress Plugin Sports Rankings and Lists Cross-Site Scripting (3.5)
WordPress Plugin Integration for Contact Form 7 and Salesforce Cross-Site Scripting (1.2.4)
WordPress Plugin Booking Calendar Cross-Site Request Forgery (4.1.5)
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-5084)