plugin

Woocommerce Payments Vulnerabilities

17 known security issues reported for the Woocommerce Payments WordPress plugin. Most recent disclosed Mar 30, 2026.

1 critical 6 medium

Running Woocommerce Payments on your site? Check whether your installed version is affected.

Scan your site free

WooPayments <= 10.5.1 - Missing Authorization to Unauthenticated Plugin Settings Update via save_upe_appearance_ajax

medium

The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin settin...

CVSS:
6.5
Affected:
up to 10.5.1
Fixed in:
10.6.0
Disclosed:
Mar 30, 2026

CVE-2026-1710 on NVD →

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 6.7.0

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.

Affected:
up to 6.7.0
Fixed in:
6.7.0
Disclosed:
Dec 31, 2023

CVE-2023-51503 on NVD →

WooPayments – Fully Integrated Solution Built and Supported by Woo <= 6.6.2 - Unauthenticated Insecure Direct Object Reference

medium

The WooPayments – Fully Integrated Solution Built and Supported by Woo plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.6.2 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access unintended objects.

CVSS:
5.3
Affected:
up to 6.6.2
Fixed in:
6.7.0
Disclosed:
Dec 27, 2023

CVE-2023-51503 on NVD →

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.9.1

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.

Affected:
up to 5.9.1
Fixed in:
5.9.1
Disclosed:
Dec 20, 2023

CVE-2023-35916 on NVD →

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.9.1

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.

Affected:
up to 5.9.1
Fixed in:
5.9.1
Disclosed:
Dec 20, 2023

CVE-2023-35915 on NVD →

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 6.5.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.

Affected:
up to 6.5.0
Fixed in:
6.5.0
Disclosed:
Dec 14, 2023

CVE-2023-49828 on NVD →

WooCommerce Payments <= 6.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WooCommerce Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in p...

CVSS:
6.4
Affected:
up to 6.4.2
Fixed in:
6.5.0
Disclosed:
Dec 5, 2023

CVE-2023-49828 on NVD →

WooCommerce Payments <= 5.9.0 - Authenticated (Shop manager+) SQL Injection via currency parameters

medium

The WooCommerce Payments plugin for WordPress is vulnerable to SQL Injection via the ‘currency', 'currency_is', and 'currency_is_not' parameters in versions up to, and including, 5.9.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i...

CVSS:
6.6
Affected:
up to 5.9.0
Fixed in:
5.9.1
Disclosed:
Jun 20, 2023

CVE-2023-35915 on NVD →

WooCommerce Payments <= 5.9.0 - Missing Authorization via redirect_pay_for_order_to_update_payment_method

medium

The WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the redirect_pay_for_order_to_update_payment_method function in versions up to, and including, 5.9.0. This makes it possible for unauthenticated attackers to change payment information f...

CVSS:
6.5
Affected:
up to 5.9.0
Fixed in:
5.9.1
Disclosed:
Jun 19, 2023

CVE-2023-35916 on NVD →

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2

unknown

[en] An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated...

Affected:
up to 5.6.2
Fixed in:
5.6.2
Disclosed:
Apr 12, 2023

CVE-2023-28121 on NVD →

WooCommerce Payments 4.8.0 - 5.6.1 Authentication Bypass and Privilege Escalation

critical

The WooCommerce Payments plugin is vulnerable to authentication bypass via the determine_current_user_for_platform_checkout function. This allows unauthenticated attackers to impersonate arbitrary users and perform some actions as the impersonated user, which can lead to site takeover.

CVSS:
9.8
Affected:
4.8.0 – 5.6.1
Fixed in:
5.6.2
Disclosed:
Mar 23, 2023

CVE-2023-28121 on NVD →

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2

unknown

Update the WordPress WooCommerce Payments plugin to the latest available version (at least 5.6.2). Michael Mazzolini discovered and reported this Privilege Escalation vulnerability in WordPress WooCommerce Payments Plugin. This could allow a malicious actor to escalate their low privileged account to something with hig...

Affected:
up to 5.6.2
Fixed in:
5.6.2
Disclosed:
Mar 23, 2023

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2

unknown

The WooCommerce Payments plugin is vulnerable to authentication bypass via the determine_current_user_for_platform_checkout function. This allows unauthenticated attackers to impersonate arbitrary users and perform some actions as the impersonated user, which can lead to site takeover.

Affected:
up to 5.6.2
Fixed in:
5.6.2
Disclosed:
Mar 23, 2023

WooCommerce Payments <= 4.5.0 - Payment Bypass

medium

The WooCommerce Payments plugin for WordPress is vulnerable to payment bypass in versions up to, and including, 4.5.0. This is due to insufficient controls on checkout payment intent. This makes it possible for unauthenticated users to complete purchases without paying for them.

CVSS:
5.3
Affected:
3.9.0 – 3.9.4, 4.0.0 – 4.0.3, 4.1.0 – 4.1.1, 4.2.0 – 4.2.2, 4.3.0 – 4.3.1, 4.4.0 – 4.4.1, 4.5.0 – 4.5.0
Fixed in:
3.9.4
Disclosed:
Aug 9, 2022

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.5.1

unknown

The WooCommerce Payments plugin for WordPress is vulnerable to payment bypass in versions up to, and including, 4.5.0. This is due to insufficient controls on checkout payment intent. This makes it possible for unauthenticated users to complete purchases without paying for them.

Affected:
up to 4.5.1
Fixed in:
4.5.1
Disclosed:
Aug 9, 2022

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.5.1

unknown

The plugin allows customer to complete an order on a merchant&rsquo;s site without paying for it.

Affected:
up to 4.5.1
Fixed in:
4.5.1

WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.9.0

unknown

The plugin does not have CSRF check when suspending and activating subscriptions, which could allow attackers to make a logged in admin suspend or activate arbitrary subscription via a CSRF attack

Affected:
up to 4.9.0
Fixed in:
4.9.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database