Known Vulnerabilities for Woocommerce Payments by Automattic
Listed below are 1 of the newest known vulnerabilities associated with "Woocommerce Payments" by "Automattic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-28180 json | Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-13399 json | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-13329 json | The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validat... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-12966 json | The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCo... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-9618 json | The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-9284 json | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclos... | Not Provided | 2026-05-23 | 2026-05-26 |
| CVE-2025-14073 json | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Dir... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2023-28121 json | An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send r... | 9.8 - CRITICAL | 2023-04-12 | 2023-12-18 |