← WordPress Vulnerabilities
WordPress security by component

WooPayments: Integrated WooCommerce Payments

WooPayments: Integrated WooCommerce Payments is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Mar 31, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: woocommerce-payments

CVE-2026-1710: WooPayments: Integrated WooCommerce Payments: A security weakness

WooPayments: Integrated WooCommerce Payments is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 10.5.1.

PublishedMar 31, 2026
Known safe version> 10.5.1
Safe version
Mar 31, 2026 CVE-2026-1710
WooPayments: Integrated WooCommerce Payments: A security weakness
WooPayments: Integrated WooCommerce Payments is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 10.5.1.
> 10.5.1
CVE6.5
NVDPending
Dec 31, 2023 CVE-2023-51503
WooPayments – Fully Integrated Solution Built and Supported by Woo: A security weakness
WooPayments – Fully Integrated Solution Built and Supported by Woo is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.9
NVD7.5
Dec 20, 2023 CVE-2023-35916
WooPayments – Fully Integrated Solution Built and Supported by Woo: A security weakness
WooPayments – Fully Integrated Solution Built and Supported by Woo is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Dec 20, 2023 CVE-2023-35915
WooPayments – Fully Integrated Solution Built and Supported by Woo: SQL injection
WooPayments – Fully Integrated Solution Built and Supported by Woo is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD9.8
Dec 14, 2023 CVE-2023-49828
WooPayments – Fully Integrated Solution Built and Supported by Woo: Cross-site scripting
WooPayments – Fully Integrated Solution Built and Supported by Woo is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Apr 12, 2023 CVE-2023-28121
Woocommerce Payments: A security weakness
Woocommerce Payments is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8