Description
WordPress Plugin WooCommerce-Store Toolkit is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin WooCommerce-Store Toolkit version 1.5.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.8 or latest
References
http://www.pritect.net/blog/visser-labs-wordpress-plugins-multiple-vulnerabilities
https://wordpress.org/plugins/woocommerce-store-toolkit/changelog/
Related Vulnerabilities
WordPress Plugin WP to Twitter Security Bypass (3.2.19)
WordPress Plugin Easy Social Feed-Social Photos Gallery-Post Feed-Like Box Security Bypass (6.3.3)
WordPress Plugin Fast Secure Contact Form-Clockwork SMS Cross-Site Scripting (2.1.2)
WordPress Plugin Modern Events Calendar Lite Security Bypass (5.1.6)
Joomla! Core 3.6.0 Cross-Site Request Forgery (3.6.0 - 3.6.0)