Description
WordPress Plugin WooCommerce-Store Toolkit is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin WooCommerce-Store Toolkit version 1.5.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.8 or latest
References
http://www.pritect.net/blog/visser-labs-wordpress-plugins-multiple-vulnerabilities
https://wordpress.org/plugins/woocommerce-store-toolkit/changelog/
Related Vulnerabilities
ownCloud Improper Input Validation Vulnerability (CVE-2013-1939)
PHP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2023-3823)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-43559)
WordPress Plugin Duplicator-WordPress Migration Arbitrary File Download (1.3.26)
WordPress Plugin WP Armour-Honeypot Anti Spam Cross-Site Scripting (1.5.6)