Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | WooCommerce Payments WordPress Plugin | Fixed version 5.6.2 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WooCommerce Payments: Unauthorized Admin Access Exploit | https://github.com/gbrsh/CVE-2023-28121 | POC Details |
| 2 | CVE-2023-28121 - WooCommerce Payments < 5.6.2 - Unauthenticated Privilege Escalation [ Mass Add Admin User ] | https://github.com/im-hanzou/Mass-CVE-2023-28121 | POC Details |
| 3 | CVE-2023-28121 - WooCommerce Payments < 5.6.2 - Unauthenticated Privilege Escalation [ Mass Add Admin User ] | https://github.com/rio128128/Mass-CVE-2023-28121-kdoec | POC Details |
| 4 | None | https://github.com/C04LA/CVE-2023-28121 | POC Details |
| 5 | Python 2.7 | https://github.com/Jenderal92/WP-CVE-2023-28121 | POC Details |
| 6 | None | https://github.com/1337nemojj/CVE-2023-28121 | POC Details |
| 7 | WooCommerce Payments =< 5.6.1 CVE-2023-28121 PoC | https://github.com/sug4r-wr41th/CVE-2023-28121 | POC Details |
| 8 | An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-28121.yaml | POC Details |
| 9 | None | https://github.com/0axz-tools/CVE-2023-28121 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-27032 | PrestaShop SQL注入漏洞 | |
| CVE-2023-30512 | CubeFS 安全漏洞 | |
| CVE-2023-29581 | yasm 安全漏洞 | |
| CVE-2023-29580 | yasm 安全漏洞 | |
| CVE-2023-29574 | Bento4 安全漏洞 | |
| CVE-2023-29571 | Cesanta MJS 安全漏洞 | |
| CVE-2023-28488 | Connman 缓冲区错误漏洞 | |
| CVE-2023-27826 | Seowon Intech SWC 5100W WIMAX Bootloader 操作系统命令注入漏洞 | |
| CVE-2023-27775 | LiveAction LiveSP 跨站脚本漏洞 | |
| CVE-2023-27704 | Void Tools 安全漏洞 | |
| CVE-2023-27703 | PikPak 安全漏洞 | |
| CVE-2023-27216 | D-Link DSL-3782 操作系统命令注入漏洞 | |
| CVE-2023-27830 | TightVNC 安全漏洞 | |
| CVE-2023-26852 | Textpattern CMS 代码问题漏洞 | |
| CVE-2023-23591 | Terminalfour 安全漏洞 | |
| CVE-2023-22897 | Securepoint Unified Threat Management 安全漏洞 | |
| CVE-2023-22620 | Securepoint Unified Threat Management 信息泄露漏洞 | |
| CVE-2023-22616 | Insyde InsydeH2O 安全漏洞 | |
| CVE-2023-1990 | Linux kernel 资源管理错误漏洞 | |
| CVE-2023-1906 | ImageMagick 缓冲区错误漏洞 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet