CVE-2026-1710: WooPayments <= 10.5.1 - Missing Authorization to Unauthenticated Plugin Settings Update via save_upe_appearance_ajax
The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saveupeappearanceajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1710?
CVE-2026-1710 has been assigned a medium severity rating due to its impact on unauthorized data modification.
How do I fix CVE-2026-1710?
To fix CVE-2026-1710, update WooPayments to version 10.5.2 or later, which includes a proper capability check for the affected function.
What systems are affected by CVE-2026-1710?
CVE-2026-1710 affects WooPayments versions up to and including 10.5.1 on WordPress websites.
What types of attacks can exploit CVE-2026-1710?
CVE-2026-1710 can be exploited by unauthenticated attackers to modify plugin settings without authorization.
Is user action required to mitigate CVE-2026-1710?
Yes, users must manually update to the patched version of WooPayments to mitigate CVE-2026-1710.