Description
WordPress Plugin WooCommerce Admin is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently leak analytics reports. WordPress Plugin WooCommerce Admin version 2.6.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin versions 1.0.4,1.1.4,1.2.5,1.3.3,1.4.1,1.5.1,1.6.4,1.7.4,1.8.4,1.9.1,2.0.4,2.1.6,2.2.7,2.3.2,2.4.5,2.5.2,2.6.4 or latest
References
Related Vulnerabilities
PrestaShop Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2018-7491)
WordPress Plugin BackupBuddy Arbitrary File Download (8.7.4.1)
Apache HTTP Server Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2007-6420)
WordPress Plugin Contact Form Entries-Contact Form 7, WPforms and more Cross-Site Scripting (1.1.6)
WordPress Plugin AppPresser-Mobile App Framework Cross-Site Scripting (1.1.4)