What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
Explanation of Vulnerability in Simple Terms
02Summary
WooPayments versions up to 5.9.0 expose sensitive payment and customer data to unauthenticated attackers over the network. The vulnerability allows direct access to confidential information without requiring user interaction or special conditions. No integrity or availability impact has been confirmed. Update to a version newer than 5.9.0 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive payment and customer data without authentication.
Potential impact on your site
04Site Impact
Customer payment details and personal information may be exposed to unauthorized parties.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 20, 2023
CVE published
April 28, 2026
Record updated