PLUGIN SECURITY

Is Woocommerce Payments safe?

Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.

What this plugin does

  • Slug: woocommerce-payments
  • Author: WooCommerce
  • 800000+ active installs
  • 68/100 rating (167 reviews on wordpress.org)
  • 45040645 all-time downloads
  • On WordPress.org since 2020-04-08

apple paycredit cardgoogle paypaymentwoocommerce payments

Maintenance status

  • Latest known version: 11.0.0
  • Last updated: 2026-08-20 12:43pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

6 known CVEs on file for Woocommerce Payments. Reported between 2022 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-1710 WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 10.6.0 Improper Authorization Medium 6.5 < 10.6.0 10.6.0 2026-03-30 ✓ fixed in latest
CVE-2023-51503 WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 6.7.0 Authorization Bypass Through User-Controlled Key Medium 5.9 < 6.7.0 6.7.0 2023-12-27 ✓ fixed in latest
CVE-2023-49828 WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 6.5.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 6.5.0 6.5.0 2023-12-05 ✓ fixed in latest
CVE-2023-35915 WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.9.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 5.9.1 5.9.1 2023-06-20 ✓ fixed in latest
CVE-2023-35916 WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.9.1 Authorization Bypass Through User-Controlled Key High 7.5 < 5.9.1 5.9.1 2023-06-19 ✓ fixed in latest
CVE-2023-28121 WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2 Improper Authentication Critical 9.8 < 5.6.2 5.6.2 2023-03-23 ✓ fixed in latest
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2 Unknown < 5.6.2 5.6.2 2023-03-23 ✓ fixed in latest
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.5.1 Unknown < 4.5.1 4.5.1 2022-08-09 ✓ fixed in latest
+ 5 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.5.1 Unknown < 4.5.1 4.5.1 ✓ fixed in latest
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.9.0 Unknown < 4.9.0 4.9.0 ✓ fixed in latest
CVE-2023-28121 WooCommerce Payments < 5.6.2 - Unauthenticated Privilege Escalation Unknown < 5.6.2 5.6.2 ✓ fixed in latest
WooCommerce Payments < 4.5.1 - Intent Parameter Tampering Unknown < 4.5.1 4.5.1 ✓ fixed in latest
WooCommerce Payments < 4.9.0 - Subscription Suspension/Activation via CSRF Unknown < 4.9.0 4.9.0 ✓ fixed in latest

How to fix it

Keep Woocommerce Payments updated — 11.0.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.