← back to popular plugins
wordfence / plugin · woocommerce-payments

WooPayments: Integrated WooCommerce Payments

woocommerce-payments
total installs
900,000
total vulns
1
critical
0
high
0
medium
1
low
0
latest vuln
patched
1
unpatched
0
avg time to patch
vulnerabilities (1)
WooPayments <= 10.5.1 - Missing Authorization to Unauthenticated Plugin Settings Update via save_upe_appearance_ajax
medium ✓ patched
cvss score 6.5
cwe CWE-285: Improper Authorization
published Mar 30, 2026
The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin settings.