Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical1
High0
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-04-08

CVE-2026-1710 - Woocommerce Payments Plugin

The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin settings.

PLUGIN Woocommerce Payments

CVE-2026-1710

MEDIUM CVSS 6.5 2026-03-31
Threat Entry Updated 2024-11-21

CVE-2023-28121 - Woocommerce Payments Plugin

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

PLUGIN Woocommerce Payments

CVE-2023-28121

CRITICAL CVSS 9.8 2023-04-12
Scroll to top