An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.
CVE-2023-28121
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2023-04-12. NVD baseline CVSS 9.8; sources differ by 0.0.
- High exploitation likelihood — EPSS 87%
- Public exploit code is available (Metasploit, epss top5pct, epss high, public exploit)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(medium)
- EG Risk
- 83(Track*)EG Risk 83/100SSVC: Track*
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation87% × 40%Automatability30% × 15%Action: Watch closely — could escalate to Attend. - EPSS PROB
- 87%
- EPSS %ILE
- 100%
- KEV
- Not listed
Published
April 12, 2023
Last Modified
November 21, 2024
Advisory Details (2)
Auto-updated Jul 29, 2026Patch Diffing CVE-2023-28121 to Compromise a … | RCE Security
https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/Critical Vulnerability Patched in WooCommerce Payments – What You Need to Know (Sept 2023 Update) – The WooCommerce Developer Blog
https://developer.woocommerce.com/2023/03/23/critical-vulnerability-detected-in-woocommerce-payments-what-you-need-to-know/Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 1× in last 7d / 15× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-24 14:15 UTCEPSS rescore
- 2026-07-23 02:20 UTCEG score recompute
- 2026-07-22 23:08 UTCEG score recompute
- 2026-07-22 14:06 UTCEPSS rescore
- 2026-07-22 14:06 UTCEPSS rescore
- 2026-07-21 15:23 UTCEPSS rescore
- 2026-07-19 02:27 UTCEPSS rescore
- 2026-07-19 02:27 UTCEPSS rescore
- 2026-07-15 16:56 UTCEPSS rescore
- 2026-07-15 16:56 UTCEPSS rescore
- 2026-07-13 06:11 UTCEPSS rescore
- 2026-07-13 06:11 UTCEPSS rescore
- 2026-07-12 05:45 UTCEPSS rescore
- 2026-07-04 06:29 UTCEPSS rescore
- 2026-07-01 15:04 UTCEPSS rescore
- 2026-06-27 03:07 UTCEPSS rescore
- 2026-06-24 14:03 UTCEPSS rescore
- 2026-06-24 14:03 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-21 01:58 UTCEPSS rescore
- 2026-06-21 01:58 UTCEPSS rescore
- 2026-06-17 17:51 UTCEPSS rescore
- 2026-06-17 17:51 UTCEPSS rescore
- 2026-06-15 17:47 UTCEPSS rescore
Show 14 moreShow fewer
- 2026-06-14 23:16 UTCEPSS rescore
- 2026-06-10 22:17 UTCEPSS rescore
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-27 13:39 UTCEPSS rescore
- 2026-05-27 13:39 UTCEPSS rescore
- 2026-05-26 13:43 UTCEPSS rescore
- 2026-05-26 13:43 UTCEPSS rescore
- 2026-05-25 03:10 UTCEG score recompute
- 2026-05-25 03:10 UTCGHSA enrichment
Publicly available exploits
(4 references)Working exploit code is in the public domain (1 Metasploit module) (2 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCim-hanzou/Mass-CVE-2023-28121First seen Jul 12, 2023
CVE-2023-28121 - WooCommerce Payments < 5.6.2 - Unauthenticated Privilege Escalation [ Mass Add Admin User ]
Open source ↗ - GitHub PoCgbrsh/CVE-2023-28121First seen Mar 30, 2023
WooCommerce Payments: Unauthorized Admin Access Exploit
Open source ↗ - Metasploitauxiliary/scanner/http/wp_woocommerce_payments_add_user✓ verifiedFirst seen Mar 22, 2023
Wordpress Plugin WooCommerce Payments Unauthenticated Admin Creation
Open source ↗ - Nucleihttp/cves/2023/CVE-2023-28121.yamlFirst seen Jan 1, 2023
WooCommerce Payments - Unauthorized Admin Access
Open source ↗
Related CVEs(same CWE)
Same CWE
10 shownCWE-287
Frequently asked(5)
What is CVE-2023-28121?
When was CVE-2023-28121 disclosed?
Is CVE-2023-28121 actively exploited?
What is the CVSS score of CVE-2023-28121?
How do I remediate CVE-2023-28121?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2023-28121
Is Your Infrastructure Affected by CVE-2023-28121?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.