A flaw in the design of WordPress allows a popular e-commerce plugin, WooCommerce, to give attackers complete control of the site. WooCommerce is an eCommerce plugin for WordPress, with which anyone can create their own online store. According to the official Plugin page on wordpress.org, there are more than 4 million active installations of the plugin.

When plugins are installed in WordPress that do not use their own authentication method, they create new roles in the WordPress authentication system, changing the elements that each new role has access to.
According to Simon Scannell, a researcher at RIPS Tech, when WooCommerce is installed, a new role called “Shop Manager” is created that has the “edit_users” capability. With this capability, Shop Managers can change the permissions of any WordPress user, including the administrator.
Since site administrators don't want plugin users to be able to edit the Administrator account and its permissions, WooCommerce has created a feature that prevents Shop Managers from editing users who are Administrators. However, the only way to disable a plugin is to either use an Administrator account or delete the plugin files. This is where the critical security flaw was discovered!
Scannel discovered a vulnerability in WooCommerce 3.4.5, as well as in all older versions. The vulnerability exploits the plugin's ability to delete logs. What was discovered is that Shop Managers could access different folders than the ones where the logs were located, and this was done by adding the command “..” to the php argument
An example of exploiting the vulnerability is the command to delete the path: ../../plugins/woocommerce-3.4.5/woocommerce.php. With this command, the user could “go up” 2 levels into the WordPress subfolders, and delete the woocommerce.php file. By deleting woocommerce.php, the entire plugin is disabled, and the function that restricts Shop Managers stops working, giving them the ability to change the permissions of all users, including Administrators.
It should be noted that to exploit the vulnerability, the attacker would first need to have access to an account with Shop_Manager privileges. The only possible ways to do this are either through phishing, or an inside job.
Finally, the vulnerability has been fixed with version 3.4.6 of WooCommerce, which was released on October 11, which we recommend you install immediately.
