WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WooPayments: Integrated WooCommerce Payments

Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.

7Reported vulnerabilities
9.8Highest CVSS score
11.0.0Latest version
800,000+Active installs

What to do now

Update WooPayments: Integrated WooCommerce Payments to 10.6.0 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 5, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-28121 Critical 9.8 86.5% 4.8.0 up to (but not including) 4.8.2
5.0.0 up to (but not including) 5.0.4
5.1.0 up to (but not including) 5.1.3
5.2.0 up to (but not including) 5.2.2
5.5.0 up to (but not including) 5.5.2
5.6.0 up to (but not including) 5.6.2
4.9.0 to 4.9.0 (inclusive)
5.3.0 to 5.3.0 (inclusive)
5.4.0 to 5.4.0 (inclusive)
4.8.2 April 12, 2023
CVE-2023-35915 Medium 6.6 0.7% 5.9.0 and earlier 5.9.1 June 20, 2023
CVE-2023-35916 Medium 6.5 0.6% 5.9.0 and earlier 5.9.1 June 19, 2023
CVE-2026-1710 Medium 6.5 0.3% 0 to 10.5.1 (inclusive) 10.6.0 March 31, 2026
CVE-2023-49828 Medium 6.4 0.4% 6.4.2 and earlier 6.5.0 December 5, 2023
CVE-2023-51503 Medium 5.3 0.5% 6.6.2 and earlier 6.7.0 December 27, 2023
WF-9d604200-91b0-4885-8fe2-1323b9d6fed5 Medium 5.3 3.9.0 up to (but not including) 3.9.4
4.0.0 up to (but not including) 4.0.3
4.1.0 up to (but not including) 4.1.1
4.2.0 up to (but not including) 4.2.2
4.3.0 up to (but not including) 4.3.1
4.4.0 up to (but not including) 4.4.1
4.5.0 to 4.5.0 (inclusive)
3.9.4 August 9, 2022

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.