Description
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-02T12:30:24.170Z
Reserved: 2023-03-10T00:00:00.000Z
Link: CVE-2023-28121
No data.
Status : Modified
Published: 2023-04-12T21:15:28.057
Modified: 2024-11-21T07:54:26.807
Link: CVE-2023-28121
No data.
OpenCVE Enrichment
No data.
Weaknesses