.. / CVE-2023-28121

Exploit for WooCommerce Payments - Unauthorized Admin Access (CVE-2023-28121)

Description:

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

Nuclei Template

View the template here CVE-2023-28121.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2023/CVE-2023-28121.yaml
Copy

References:

https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/
https://woocommerce.com/products/woocommerce-payments/
https://developer.woocommerce.com/2023/03/23/critical-vulnerability-detected-in-woocommerce-payments-what-you-need-to-know/
https://nvd.nist.gov/vuln/detail/CVE-2023-28121
https://github.com/gbrsh/CVE-2023-28121