WordPress WooCommerce Payments Plugin Authentication Bypass (CVE-2023-28121)

Related Vulnerabilities: CVE-2023-28121  

Check Point Reference: CPAI-2023-0561 Date Published: 27 Jul 2023 Severity: Critical Last Updated: Sunday 17 December, 2023 Source: Industry Reference:CVE-2023-28121
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? WordPress WooCommerce Payments plugin from and including 4.8.0 up to and excluding 4.8.2
WordPress WooCommerce Payments plugin 4.9.0

WordPress WooCommerce Payments plugin from and including 5.0.0 up to and excluding to 5.0.4

WordPress WooCommerce Payments plugin from and including 5.1.0 up to and excluding 5.1.3
WordPress WooCommerce Payments plugin from and including 5.2.0 up to and excluding 5.2.2
WordPress WooCommerce Payments plugin version 5.3.0
WordPress WooCommerce Payments plugin version 5.4.0
WordPress WooCommerce Payments plugin from and including 5.5.0 up to and excluding 5.5.2

WordPress WooCommerce Payments plugin from and including 5.6.0 up to and excluding 5.6.2 Vulnerability Description An authentication bypass vulnerability exists in WordPress WooCommerce Payments plugin. Successful exploitation of this vulnerability would allow remote attackers to gain unauthorized access into the affected system.