PLUGIN SECURITY
Is Woocommerce Payments safe?
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
What this plugin does
- Slug:
woocommerce-payments - Author: WooCommerce
- 800000+ active installs
- 68/100 rating (167 reviews on wordpress.org)
- 45040645 all-time downloads
- On WordPress.org since 2020-04-08
apple paycredit cardgoogle paypaymentwoocommerce payments
Maintenance status
- Latest known version: 11.0.0
- Last updated: 2026-08-20 12:43pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
6 known CVEs on file for Woocommerce Payments. Reported between 2022 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-1710 | WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 10.6.0 | Improper Authorization | Medium 6.5 | < 10.6.0 | 10.6.0 | 2026-03-30 | ✓ fixed in latest |
| CVE-2023-51503 | WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 6.7.0 | Authorization Bypass Through User-Controlled Key | Medium 5.9 | < 6.7.0 | 6.7.0 | 2023-12-27 | ✓ fixed in latest |
| CVE-2023-49828 | WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 6.5.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 6.5.0 | 6.5.0 | 2023-12-05 | ✓ fixed in latest |
| CVE-2023-35915 | WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.9.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.6 | < 5.9.1 | 5.9.1 | 2023-06-20 | ✓ fixed in latest |
| CVE-2023-35916 | WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.9.1 | Authorization Bypass Through User-Controlled Key | High 7.5 | < 5.9.1 | 5.9.1 | 2023-06-19 | ✓ fixed in latest |
| CVE-2023-28121 | WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2 | Improper Authentication | Critical 9.8 | < 5.6.2 | 5.6.2 | 2023-03-23 | ✓ fixed in latest |
| — | WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 5.6.2 | — | Unknown | < 5.6.2 | 5.6.2 | 2023-03-23 | ✓ fixed in latest |
| — | WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.5.1 | — | Unknown | < 4.5.1 | 4.5.1 | 2022-08-09 | ✓ fixed in latest |
+ 5 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.5.1 | — | Unknown | < 4.5.1 | 4.5.1 | — | ✓ fixed in latest |
| — | WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 4.9.0 | — | Unknown | < 4.9.0 | 4.9.0 | — | ✓ fixed in latest |
| CVE-2023-28121 | WooCommerce Payments < 5.6.2 - Unauthenticated Privilege Escalation | — | Unknown | < 5.6.2 | 5.6.2 | — | ✓ fixed in latest |
| — | WooCommerce Payments < 4.5.1 - Intent Parameter Tampering | — | Unknown | < 4.5.1 | 4.5.1 | — | ✓ fixed in latest |
| — | WooCommerce Payments < 4.9.0 - Subscription Suspension/Activation via CSRF | — | Unknown | < 4.9.0 | 4.9.0 | — | ✓ fixed in latest |
How to fix it
Keep Woocommerce Payments updated — 11.0.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WooCommerce PayPal Payments — 800000+ active installs — 56/100 (577) — max PHP 8.4
- WooCommerce Stripe Payment Gateway — 700000+ active installs — 62/100 (235) — max PHP 8.4
- Payment Plugins for Stripe WooCommerce — 100000+ active installs — 96/100 (301) — max PHP 8.4
- Mollie Payments for WooCommerce — 100000+ active installs — 70/100 (70)
- WooCommerce Square — 80000+ active installs — 42/100 (121)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.