WooPayments <= 10.5.1 - Missing Authorization to Unauthenticated Plugin Settings Update via save_upe_appearance_ajax
medium
The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin settin...
- CVSS:
- 6.5
- Affected:
- up to 10.5.1
- Fixed in:
- 10.6.0
- Disclosed:
- Mar 30, 2026
CVE-2026-1710 on NVD →
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 6.7.0
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.
- Affected:
- up to 6.7.0
- Fixed in:
- 6.7.0
- Disclosed:
- Dec 31, 2023
CVE-2023-51503 on NVD →
WooPayments – Fully Integrated Solution Built and Supported by Woo <= 6.6.2 - Unauthenticated Insecure Direct Object Reference
medium
The WooPayments – Fully Integrated Solution Built and Supported by Woo plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.6.2 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access unintended objects.
- CVSS:
- 5.3
- Affected:
- up to 6.6.2
- Fixed in:
- 6.7.0
- Disclosed:
- Dec 27, 2023
CVE-2023-51503 on NVD →
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.9.1
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
- Affected:
- up to 5.9.1
- Fixed in:
- 5.9.1
- Disclosed:
- Dec 20, 2023
CVE-2023-35916 on NVD →
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.9.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
- Affected:
- up to 5.9.1
- Fixed in:
- 5.9.1
- Disclosed:
- Dec 20, 2023
CVE-2023-35915 on NVD →
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 6.5.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.
- Affected:
- up to 6.5.0
- Fixed in:
- 6.5.0
- Disclosed:
- Dec 14, 2023
CVE-2023-49828 on NVD →
WooCommerce Payments <= 6.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WooCommerce Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in p...
- CVSS:
- 6.4
- Affected:
- up to 6.4.2
- Fixed in:
- 6.5.0
- Disclosed:
- Dec 5, 2023
CVE-2023-49828 on NVD →
WooCommerce Payments <= 5.9.0 - Authenticated (Shop manager+) SQL Injection via currency parameters
medium
The WooCommerce Payments plugin for WordPress is vulnerable to SQL Injection via the ‘currency', 'currency_is', and 'currency_is_not' parameters in versions up to, and including, 5.9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i...
- CVSS:
- 6.6
- Affected:
- up to 5.9.0
- Fixed in:
- 5.9.1
- Disclosed:
- Jun 20, 2023
CVE-2023-35915 on NVD →
WooCommerce Payments <= 5.9.0 - Missing Authorization via redirect_pay_for_order_to_update_payment_method
medium
The WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the redirect_pay_for_order_to_update_payment_method function in versions up to, and including, 5.9.0. This makes it possible for unauthenticated attackers to change payment information f...
- CVSS:
- 6.5
- Affected:
- up to 5.9.0
- Fixed in:
- 5.9.1
- Disclosed:
- Jun 19, 2023
CVE-2023-35916 on NVD →
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2
unknown
[en] An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated...
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.2
- Disclosed:
- Apr 12, 2023
CVE-2023-28121 on NVD →
WooCommerce Payments 4.8.0 - 5.6.1 Authentication Bypass and Privilege Escalation
critical
The WooCommerce Payments plugin is vulnerable to authentication bypass via the determine_current_user_for_platform_checkout function. This allows unauthenticated attackers to impersonate arbitrary users and perform some actions as the impersonated user, which can lead to site takeover.
- CVSS:
- 9.8
- Affected:
- 4.8.0 – 5.6.1
- Fixed in:
- 5.6.2
- Disclosed:
- Mar 23, 2023
CVE-2023-28121 on NVD →
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2
unknown
Update the WordPress WooCommerce Payments plugin to the latest available version (at least 5.6.2).
Michael Mazzolini discovered and reported this Privilege Escalation vulnerability in WordPress WooCommerce Payments Plugin. This could allow a malicious actor to escalate their low privileged account to something with hig...
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.2
- Disclosed:
- Mar 23, 2023
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2
unknown
The WooCommerce Payments plugin is vulnerable to authentication bypass via the determine_current_user_for_platform_checkout function. This allows unauthenticated attackers to impersonate arbitrary users and perform some actions as the impersonated user, which can lead to site takeover.
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.2
- Disclosed:
- Mar 23, 2023
WooCommerce Payments <= 4.5.0 - Payment Bypass
medium
The WooCommerce Payments plugin for WordPress is vulnerable to payment bypass in versions up to, and including, 4.5.0. This is due to insufficient controls on checkout payment intent. This makes it possible for unauthenticated users to complete purchases without paying for them.
- CVSS:
- 5.3
- Affected:
- 3.9.0 – 3.9.4, 4.0.0 – 4.0.3, 4.1.0 – 4.1.1, 4.2.0 – 4.2.2, 4.3.0 – 4.3.1, 4.4.0 – 4.4.1, 4.5.0 – 4.5.0
- Fixed in:
- 3.9.4
- Disclosed:
- Aug 9, 2022
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.5.1
unknown
The WooCommerce Payments plugin for WordPress is vulnerable to payment bypass in versions up to, and including, 4.5.0. This is due to insufficient controls on checkout payment intent. This makes it possible for unauthenticated users to complete purchases without paying for them.
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.1
- Disclosed:
- Aug 9, 2022
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.5.1
unknown
The plugin allows customer to complete an order on a merchant’s site without paying for it.
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.1
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.9.0
unknown
The plugin does not have CSRF check when suspending and activating subscriptions, which could allow attackers to make a logged in admin suspend or activate arbitrary subscription via a CSRF attack
- Affected:
- up to 4.9.0
- Fixed in:
- 4.9.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database