Description
WordPress Plugin WooCommerce Customers Manager is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin WooCommerce Customers Manager version 26.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 26.5 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:126143E0-B0CC-4517-862E-3AC557DB744F
https://codecanyon.net/item/woocommerce-customers-manager/10965432#item-description__change-log
Related Vulnerabilities
Moodle Incorrect Calculation Vulnerability (CVE-2022-30600)
WordPress Plugin CMS Tree Page View Cross-Site Request Forgery (1.2.4)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0165)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (4.2.1)