Description
WordPress Plugin WooCommerce Anti-Fraud is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently reset all orders' statuses to processing. WordPress Plugin WooCommerce Anti-Fraud version 3.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3 or latest
References
https://twitter.com/BrianHenryIE/status/1330300510331613185
https://dzv365zjfbd8v.cloudfront.net/changelogs/woocommerce-anti-fraud/changelog.txt
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4402)
Envoy Proxy Improper Handling of Exceptional Conditions Vulnerability (CVE-2024-23325)
WordPress Plugin Social Photo Gallery Remote Code Execution (1.0)
WordPress Plugin Simplelife Cross-Site Request Forgery (1.2)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3193)