Description
WordPress Plugin WooCommerce is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin WooCommerce version 3.4.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.4.6 or latest
References
https://www.ripstech.com/php-security-calendar-2018/#day-10
https://raw.githubusercontent.com/woocommerce/woocommerce/master/CHANGELOG.txt
Related Vulnerabilities
WordPress Plugin NextGEN Gallery-WordPress Gallery Security Bypass (3.1.6)
WebLogic CVE-2016-0574 Vulnerability (CVE-2016-0574)
Atlassian Jira Improper Authentication Vulnerability (CVE-2021-26070)
WordPress Plugin HDW Player (Video Player & Video Gallery) SQL Injection (2.4.2)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-3179)