> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Patch Diffing CVE-2023-28121 to Compromise a WooCommerce

[SOURCE] RCE Security [AUTHOR: Julien Ahrens] [DATE: 03/07/2023 16:54] [LANGUAGE: EN]
Back in March 2023, I noticed an interesting security advisory that was published by Wordfence about a critical “Authentication Bypass and Privilege Escalation” (aka CVE-2023-28121) affecting the “WooCommerce Payments” plugin which has more than 600.000 active installs according to WordPress. Since one of my customers was running a WooCommerce instance with the vulnerable version of […]
[messages.read_original_source] →