← back
CVE-2023-28121observed exploitationCWE-287

CVE-2023-28121

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 87%
from disclosure to weapon0 days
Published on NVDApr 12
1st PoCMar 30
metasploitMar 22
VulnCheck+96d
exploitation probability
87%top 1% of all CVEs
observed exploitation
yesVulnCheck
7 public exploit(s)
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.