July 14, 2023, 7:48 p.m. | Navya Harika Karaka

Rapid7 Blog blog.rapid7.com

Authentication bypass in Wordpress Plugin WooCommerce Payments


This week's Metasploit release includes a module for CVE-2023-28121 by h00die. This module can be used against any wordpress instance that uses WooCommerce payments < 5.6.1. This module exploits an auth by-pass vulnerability in the WooCommerce WordPress plugin. You can simply

auth authentication authentication bypass bypass cve cve-2023-28121 exploits instance metasploit metasploit weekly wrapup pass payments plugin release vulnerability week weekly woocommerce wordpress wordpress plugin wrap-up

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)

Vice President, Cyber Operations Engineer

@ BlackRock | LO9-London - Drapers Gardens