A critical vulnerability in the WooCommerce Payments plugin has been discovered, which poses a significant risk to all WordPress sites using this plugin. This vulnerability can allow unauthorized administrator access to a WordPress site, which potentially gives attackers full control over the website. Furthermore, once admin access is gained, they can easily execute remote code on the hosting machine, which is a serious concern.
At Secragon, we have developed a 100% working exploit for this vulnerability. However, we have made the decision not to publish it at this time, as it could put hundreds of thousands of WordPress installations at risk. Instead, we strongly urge all WooCommerce Payments users to update their plugins immediately to safeguard their websites against potential security breaches.