CVE-2023-28121
CRITICAL 9.8EPSS 86.5%
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 86.51% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- critical · CWE-287
- Published
- 2023-04-12
- Updated
- 2024-08-02
Proof-of-concept exploits (9)
- 1337nemojj/CVE-2023-281210★ · 2026-06-07
- Jenderal92/WP-CVE-2023-281211★ · 2026-05-30
- gbrsh/CVE-2023-2812141★ · 2023-05-31
- im-hanzou/Mass-CVE-2023-2812111★ · 2023-07-14
- rio128128/Mass-CVE-2023-28121-kdoec1★ · 2023-07-12
- sug4r-wr41th/CVE-2023-281210★ · 2025-04-12
- 0axz-tools/CVE-2023-28121
- luisdevpentest/CVE-2023-28121-WordPress-Privilege-Escalation
- getdrive/PoC