Feed/CVE-2023-28121
CVE-2023-28121CRITICALCVSS 9.8

CVE-2023-28121

Published Apr 12, 2023·Updated Jun 17, 2026

NVD Description

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

Public Exploits & PoCs10 found

PoC: CVE-2023-28121-WordPress-Privilege-Escalation

Exploração prática de vulnerabilidade crítica no WordPress usando o plugin WooCommerce Payments.

1

PoC: Mass-CVE-2023-28121

CVE-2023-28121 - WooCommerce Payments < 5.6.2 - Unauthenticated Privilege Escalation [ Mass Add Admin User ]

1

PoC: CVE-2023-28121

WooCommerce Payments (WordPress plugin) =< 5.6.1 CVE-2023-28121 PoC

PoC: CVE-2023-28121

WooCommerce Payments =< 5.6.1 CVE-2023-28121 PoC

PoC: CVE-2023-28121

WooCommerce Payments =< 5.6.1 CVE-2023-28121 PoC

PoC: CVE-2023-28121

Python research notes and tooling for CVE-2023-28121

PoC: WP-CVE-2023-28121

Python 2.7

PoC: CVE-2023-28121

Python 2.7

PoC: Mass-CVE-2023-28121-kdoec

CVE-2023-28121 - WooCommerce Payments < 5.6.2 - Unauthenticated Privilege Escalation [ Mass Add Admin User ]

PoC: CVE-2023-28121

WooCommerce Payments: Unauthorized Admin Access Exploit

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free