PT-2026-29191 · Automattic+1 · Woocommerce+1

Dmitry Ignatyev

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-1710

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions WooPayments versions up to and including 10.5.1
Description The WooPayments: Integrated WooCommerce Payments plugin for WordPress has a flaw that allows unauthorized modification of data. This is due to a missing capability check within the save upe appearance ajax function. An unauthenticated attacker can exploit this to update plugin settings.
Recommendations Update the WooPayments plugin to a version newer than 10.5.1.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1710

Affected Products

Woocommerce
Woopayments