Automattic Woopayments
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Automattic Woopayments.
By the Year
In 2026 there have been 0 vulnerabilities in Automattic Woopayments. Woopayments did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 5 | 8.00 |
It may take a day or so for new Woopayments vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Automattic Woopayments Security Vulnerabilities
CVE-2023-51503: Auth Bypass via User-Controlled Key in WooPayments < 6.9.2
CVE-2023-51503
7.5 - High
- December 31, 2023
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.
Insecure Direct Object Reference / IDOR
WooPayments Auth Bypass via User-Controlled Key <=5.9.0
CVE-2023-35916
7.5 - High
- December 20, 2023
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
Insecure Direct Object Reference / IDOR
WooPayments SQLi (<=5.9.0) Improper Neutralization of Special Elements
CVE-2023-35915
9.8 - Critical
- December 20, 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
SQL Injection
WooPayments Stored XSS Vulnerability in v6.4.2
CVE-2023-49828
5.4 - Medium
- December 14, 2023
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooPayments Fully Integrated Solution Built and Supported by Woo allows Stored XSS.This issue affects WooPayments Fully Integrated Solution Built and Supported by Woo: from n/a through 6.4.2.
XSS
Unauth-RNA: WooCommerce Payments <=5.6.1 Admin Escalation
CVE-2023-28121
9.8 - Critical
- April 12, 2023
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.
authentification
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Automattic Woopayments or by Automattic? Click the Watch button to subscribe.