CVE-2023-37871: Automattic Woocommerce Gocardless

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.

Affected products

  • Automattic Woocommerce Gocardless: before 2.5.7 (fixed in 2.5.7)

Published 2023-12-20. Last modified 2026-06-17.