CVE · Medium

CVE-2023-51503 — WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 6.7.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-51503 WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 6.7.0 Authorization Bypass Through User-Controlled Key Medium 5.9 < 6.7.0 6.7.0 2023-12-27

CVE-2023-51503

The WooPayments plugin for WooCommerce contained an insecure direct object reference flaw affecting versions before 6.7.0 that could enable attackers to circumvent security controls and gain unauthorized access to sensitive data or database operations. Researcher Rafie Muhammad identified and reported this vulnerability, which was subsequently patched in version 6.7.0. Users should upgrade their installation to at least this version to eliminate the risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.