MEDIUM (6.6)
    Plugin

    Unauthorized Data Modification in WooPayments Plugin for WordPress

    Published Date: 3/31/2026
    CVE ID: CVE-2026-1710

    Summary

    The WooPayments: Integrated WooCommerce Payments plugin for WordPress is susceptible to unauthorized data modification. This vulnerability exists due to a missing capability check in the 'save_upe_appearance_ajax' function, allowing unauthenticated attackers to alter plugin settings in versions up to 10.5.1.

    Vulnerability Details

    The vulnerability in the WooPayments: Integrated WooCommerce Payments plugin arises from a lack of proper user capability checks in the 'save_upe_appearance_ajax' function. This flaw allows attackers without any authentication to modify the appearance settings of the plugin, posing a risk to the integrity of the site’s payment configuration. Such unauthorized modifications could lead to various impacts, including the alteration of payment settings, potentially affecting transaction processes and site functionality. The absence of security validation increases the attack surface for malicious users who can exploit this flaw remotely. Maintaining integrity and security is critical, especially for plugins handling sensitive payment data. The developers should enforce strict access controls to protect against such vulnerabilities.

    Recommendations

    Website administrators should immediately apply workarounds to temporarily restrict access to the affected function by enforcing capability checks or disabling the plugin until a fix is available. Regularly monitoring and logging any configuration changes can help detect unauthorized modifications.

    Available Fixes

    Last Updated: 4/1/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More