For the people not yet on the latest WooFramework version: You can download the latest version of WooFramework here: http://cl.ly/2a3j1m351C3u2i0t122j (it is 5.3.10)
Do you know how to manually update the framework? This zip file unzips to a "framework" folder, you need to replace to contents of the "functions" folder of your theme. Obviously make a backup of everything before you start.
This exploit is fixed in the latest two stable builds and should have been reported to us (WooThemes team) in the first place. Wonder if this guy has ever heard of the concept of responsible disclosure...
Are you seriously suggesting downloading the fix for vulnerability from some random website?
I never receive notice to upgrade the theme in the dashboard (and the option is activated).
what do i do now ?
Seriously, if you are a representative of woothemes.com, this approach is a major fail. you have a known website, that's where your authority and trust resides. Use it.
This just looks like someone attempting to get people to add a new backdoor to their existing wootheme powered site.
Like I mentioned on GitHub, your updater is broken, so your customers aren't getting this update even if you guys did release it. See my comment for details, but it appears that the file which triggers the Update Framework feature to work has been rolled back to an old version.
Regarding your comment on 'responsible disclosure', where did you responsibly disclose this exploit to your customers and notify them that a critical update was needed to prevent, in your words "a way to cripple many (many, many, many) websites."?