#VU26023 Improper access control in Import Export WordPress Users
Published: March 12, 2020
Import Export WordPress Users
WebToffee
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper capability check in "manage_woocommerce" function when a site is running the affected plugin without WooCommerce installed. A remote authenticated attacker can use CSV file, import new users with administrative capabilities and gain complete control over the site.