A shop is a tempting target, how a payments flaw hands the panel to strangers
An online shop is a double target: it holds customer data and money. That is why bots exploit e-commerce flaws exceptionally fast. The WooCommerce Payments story from 2023 is a textbook example.
What happened
WooCommerce Payments is the official plugin for accepting payments. The flaw CVE-2023-28121 let an attacker impersonate any user, including the administrator, by adding the right header to a request. No password, no login.
The threat was serious enough that WordPress.org and the developers forced updates on hundreds of thousands of shops. Even so, as soon as the details became public, a wave of automated attacks began.
Why it is dangerous in a shop
A shop administrator is not just "content editing". It is access to orders, customer data and payment configuration. Taking over such an account can mean a leak of personal data (and real GDPR consequences) and swapping the bank account numbers for transfers.
What to do
- In a shop, treat updates as a priority, here money and customer data are at stake.
- Limit the number of administrator accounts to a minimum and enable two-factor login.
- Make frequent backups, a shop changes every day.
A shop needs more attention than a brochure site. As part of e-commerce care we keep an eye on updates, accounts and backups, let's talk about your shop.
Source: NVD, CVE-2023-28121.