CVE · Critical

CVE-2023-28121 — WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-28121 WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2 Improper Authentication Critical 9.8 < 5.6.2 5.6.2 2023-03-23

CVE-2023-28121

The WooCommerce Payments plugin through version 5.6.1 contains a vulnerability that permits unauthenticated attackers to execute requests with the privileges of higher-level users, including administrators. This flaw enables remote attackers without credentials to obtain administrative access on WordPress installations running the vulnerable plugin version.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.