The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack
https://wpscan.com/vulnerability/734dba0b-f550-4372-884a-d42f7b0c00c7/