๐Ÿ” CVE Alert

CVE-2023-28121

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

CWE CWE-287
Vendor n/a
Product woocommerce payments wordpress plugin
Published Apr 12, 2023
Last Updated Aug 2, 2024
Stay Ahead of the Next One

Get instant alerts for n/a woocommerce payments wordpress plugin

Be the first to know when new unknown vulnerabilities affecting n/a woocommerce payments wordpress plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / WooCommerce Payments WordPress Plugin
Fixed version 5.6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
developer.woocommerce.com: https://developer.woocommerce.com/2023/03/23/critical-vulnerability-detected-in-woocommerce-payments-what-you-need-to-know/ rcesecurity.com: https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/