peter bassill · operator
$ cve CVE-2023-28121 JSON

CVE-2023-28121

9.8
CRITICAL · CVSS 3.1 · EPSS 86.5% (pctl 100)

Patch early

EPSS 86.5% — above the 10% action threshold.

Description

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS86.51% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2023-04-12
Last modified2026-06-17

Affected (2)

VendorProduct
automatticwoocommerce payments
automatticwoopayments

References

→ the Explorer  ·  watch your stack  ·  NVD