rootpwn

low · CVSS v3 3.7

CVE-2026-91017

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming…

Description

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.

Scores

Severity
low
CVSS v2
2.6
CVSS v3
3.7
CVSS v4
EPSS

← All CVEs