Woopayments Automattic Woopayments

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Automattic Woopayments.

By the Year

In 2026 there have been 0 vulnerabilities in Automattic Woopayments. Woopayments did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 0 0.00
2023 5 8.00

It may take a day or so for new Woopayments vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Automattic Woopayments Security Vulnerabilities

CVE-2023-51503: Auth Bypass via User-Controlled Key in WooPayments < 6.9.2
CVE-2023-51503 7.5 - High - December 31, 2023

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.

Insecure Direct Object Reference / IDOR

WooPayments Auth Bypass via User-Controlled Key <=5.9.0
CVE-2023-35916 7.5 - High - December 20, 2023

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.

Insecure Direct Object Reference / IDOR

WooPayments SQLi (<=5.9.0) Improper Neutralization of Special Elements
CVE-2023-35915 9.8 - Critical - December 20, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.

SQL Injection

WooPayments Stored XSS Vulnerability in v6.4.2
CVE-2023-49828 5.4 - Medium - December 14, 2023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.

XSS

Unauth-RNA: WooCommerce Payments <=5.6.1 Admin Escalation
CVE-2023-28121 9.8 - Critical - April 12, 2023

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

authentification

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Automattic Woopayments or by Automattic? Click the Watch button to subscribe.

Automattic
Vendor

subscribe