WooCommerce Payments 4.8.0 - 5.6.1 Authentication Bypass and Privilege Escalation
2023-03-23 00:00
mikemyersStrategic Overview
StatusPatched in 5.6.2
Affected PluginWooPayments: Integrated WooCommerce Payments
Affected Version
4.8.0 – 5.6.1CVSS9.8Critical
CVE
CVE-2023-28121Vulnerability Overview
The WooCommerce Payments plugin is vulnerable to authentication bypass via the determine_current_user_for_platform_checkout function. This allows unauthenticated attackers to impersonate arbitrary users and perform some actions as the impersonated user, which can lead to site takeover.
Technical Analysis
REMEDIATION: Update to version 5.6.2, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C