« Volver al listado

CVE-2023-28121

Estado: ModificadaCrítica (9.8)—

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-28121",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "WooCommerce Payments WordPress Plugin",
          "versions": [
            {
              "status": "affected",
              "version": "Fixed version 5.6.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-04-12T21:15:28.057",
  "references": [
    {
      "url": "https://developer.woocommerce.com/2023/03/23/critical-vulnerability-detected-in-woocommerce-payments-what-you-need-to-know/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/",
      "source": "support@hackerone.com"
    },
    {
      "url": "https://developer.woocommerce.com/2023/03/23/critical-vulnerability-detected-in-woocommerce-payments-what-you-need-to-know/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated."
    }
  ],
  "lastModified": "2026-06-17T05:46:55.107",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:automattic:woocommerce_payments:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE70E8AE-CFBB-4575-A340-DBD17C3CE853",
              "versionEndExcluding": "4.8.2",
              "versionStartIncluding": "4.8.0"
            },
            {
              "criteria": "cpe:2.3:a:automattic:woocommerce_payments:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "519111D8-D787-4B95-91F3-9FCFF17723C3",
              "versionEndExcluding": "5.0.4",
              "versionStartIncluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:automattic:woocommerce_payments:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47F55EC1-8DE8-4BB8-9D92-23510CB191FF",
              "versionEndExcluding": "5.1.3",
              "versionStartIncluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:a:automattic:woocommerce_payments:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D29E155-A3A0-446A-A414-B3CC66D6450B",
              "versionEndExcluding": "5.2.2",
              "versionStartIncluding": "5.2.0"
            },
            {
              "criteria": "cpe:2.3:a:automattic:woocommerce_payments:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8AF27AE4-B382-4293-9E7A-1A06769DFF1D",
              "versionEndExcluding": "5.5.2",
              "versionStartIncluding": "5.5.0"
            },
            {
              "criteria": "cpe:2.3:a:automattic:woopayments:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AEB22CB8-53ED-4073-ADA9-8C87B4F0176F",
              "versionEndExcluding": "5.6.2",
              "versionStartIncluding": "5.6.0"
            },
            {
              "criteria": "cpe:2.3:a:automattic:woopayments:4.9.0:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08275EF1-5695-4CC4-A4B9-8D5429C37DB1"
            },
            {
              "criteria": "cpe:2.3:a:automattic:woopayments:5.3.0:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4D5E491-B3BB-4D91-9DD6-845A35833F20"
            },
            {
              "criteria": "cpe:2.3:a:automattic:woopayments:5.4.0:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D756027-30C4-443C-8421-62D6EFA8B2C3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}