CVE-2023-35876: Automattic Woocommerce Square

High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.

Affected products

  • Automattic Woocommerce Square: before 3.8.2 (fixed in 3.8.2)

Published 2023-12-20. Last modified 2026-06-17.