Description
WordPress Plugin WooCommerce Payments-Fully Integrated Solution Built and Supported by Woo is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently impersonate arbitrary users and perform some actions as the impersonated user, which can lead to site takeover. WordPress Plugin WooCommerce Payments-Fully Integrated Solution Built and Supported by Woo versions 4.8.0 - 5.6.1 are vulnerable.
Remediation
Update to plugin versions 4.8.2, 4.9.1, 5.0.4, 5.1.3, 5.2.2, 5.3.1, 5.4.1, 5.5.2, 5.6.2 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:0F78A245-866C-462E-BD23-43DFADB57072
https://plugins.svn.wordpress.org/woocommerce-payments/trunk/readme.txt
Related Vulnerabilities
Drupal Core 8.9.0 Cross-Site Request Forgery (8.9.0)
WordPress Plugin Advanced Access Manager Arbitrary Code Execution (2.8.2)
WordPress Plugin PowerPress Podcasting by Blubrry Cross-Site Scripting (10.0.1)
WordPress Plugin One Click SSL Cross-Site Request Forgery (1.4.6)
WordPress Plugin Spam protection, AntiSpam, FireWall by CleanTalk SQL Injection (5.153.3)