N/A
2026-03-31< 10.6.0
WordPress WooCommerce Payments Plugin <= 10.5.1 is vulnerable to Broken Access Control
Minimum safe version
10.6.0
Update to 10.6.0 or later to address 11 fixable vulnerabilities
WordPress WooCommerce Payments Plugin <= 10.5.1 is vulnerable to Broken Access Control
WordPress WooCommerce Payments Plugin <= 6.6.2 is vulnerable to Insecure Direct Object References (IDOR)
CVE-2023-49828
WooCommerce Payments < 4.9.0 - Subscription Suspension/Activation via CSRF
WooCommerce Payments < 4.5.1 - Intent Parameter Tampering
WooCommerce Payments <= 4.5.0 - Payment Bypass
CVE-2023-35916
CVE-2023-35915
CVE-2023-28121
WordPress WooCommerce Payments Plugin <= 5.6.1 is vulnerable to Privilege Escalation
WooCommerce Payments 4.8.0 - 5.6.1 Authentication Bypass and Privilege Escalation