CVE-2023-28121: Critical severity Automattic Woocommerce Payments Wordpress vulnerability
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28121?
CVE-2023-28121 is a critical vulnerability in the WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) that allows an unauthenticated attacker to gain admin access.
How severe is CVE-2023-28121?
CVE-2023-28121 is considered critical with a severity score of 9.8.
Which versions of WooCommerce Payments are affected by CVE-2023-28121?
Versions 5.6.1 and lower of the WooCommerce Payments plugin for WordPress are affected by CVE-2023-28121.
How can an attacker exploit CVE-2023-28121?
An unauthenticated attacker can exploit CVE-2023-28121 by sending requests on behalf of an elevated user, like administrator, gaining admin access.
Is there a patch available for CVE-2023-28121?
Yes, a patch is available for CVE-2023-28121. It is recommended to update to a version that is not affected.