CVE · Medium

CVE-2026-1710 — WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 10.6.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-1710 WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 10.6.0 Improper Authorization Medium 6.5 < 10.6.0 10.6.0 2026-03-30

CVE-2026-1710

The WooPayments plugin for WooCommerce Payments on WordPress has a security flaw that allows unauthorized changes to its configuration due to inadequate access controls on the 'save_upe_appearance_ajax' function in versions prior to 10.5.1, allowing anyone to modify settings without proper authorization. This vulnerability enables unverified individuals to alter plugin settings freely.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.