S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2023-28121 Scanner

CVE-2023-28121 scanner - Improper Access Control vulnerability in WooCommerce Payments plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-28121
9.8
CVSS

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WooCommerce Payments WordPress Pluginby n/a
Fixed version 5.6.2
Updated Aug 19, 2026View on NVD →
Detail

WooCommerce Payments is a plugin designed for WordPress, which allows you to accept and manage payments from your online store. This plugin simplifies the payment process and provides various payment options, including credit/debit card payments, Google Pay, Apple Pay, and others. The plugin is widely used by online businesses of all sizes and has become an essential tool for eCommerce businesses globally.

However, a major security flaw, CVE-2023-28121, has been detected in the WooCommerce Payments plugin that allows an attacker to gain access to an elevated user, such as an administrator of an online store, without any authentication. This vulnerability arises due to insufficient access control measures in the plugin's code, which enables unauthorized access by attackers to sensitive user information such as passwords, personal data, and other confidential data.

This vulnerability can lead to serious consequences for businesses, as it grants attackers full access to an online store’s administrative panel, as an elevated user. This type of access can enable attackers to steal and manipulate sensitive data, install malware, redirect traffic, and cause damage to an online brand's image and reputation. Once an attacker gains control of an online store’s administration panel, it can be challenging to detect and mitigate the attacks.

To ensure that your digital assets are secure and protected from vulnerabilities, you can leverage the pro features of the s4e.io platform. The platform enables businesses and online websites to detect vulnerabilities, assess their severity, and plan and execute remediation strategies to prevent attackers from exploiting them. With its powerful features, businesses can have peace of mind in knowing their digital assets are protected from potential threats, and vulnerabilities are proactively addressed.

 

REFERENCES

Solution Advice

To protect against this vulnerability, a few key precautions can be taken:

  • Regularly update the WooCommerce Payments plugin to the latest version to patch vulnerabilities.
  • Limit access to the plugin by ensuring that only authorized personnel have access.
  • Verify the integrity of plugins before installing them on your website.
  • Conduct regular security scans on your website to identify vulnerabilities.
  • Implement strong password policies for all accounts utilized for website administration.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.