Description
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the WordPress ЮKassa для WooCommerce plugin allows the exposure of subscriber sensitive data due to improper handling of user information. This flaw means confidential subscriber details could be read by an attacker, compromising privacy and potentially facilitating further fraud or phishing attempts. The weakness is categorized as CWE‑201 (Sensitive Data Exposure).

Affected Systems

The affected vendor is Yoomoney, whose YuKassa plugin for WooCommerce is deployed on WordPress sites. Versions 2.16.1 and earlier are vulnerable. Sites running those releases or any plugin copy with the same code paths are at risk.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows a low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the most likely attack vector involves an unauthenticated or minimally privileged attacker exploiting exposed plugin endpoints or configuration files to read subscriber information. Successful exploitation would grant access to sensitive user data, potentially leading to privacy breaches or financial loss.

Generated by OpenCVE AI on August 3, 2026 at 17:31 UTC.

Remediation

Vendor Solution

Update the WordPress ЮKassa для WooCommerce Plugin to the latest available version (at least 2.16.2).


OpenCVE Recommended Actions

  • Upgrade the WordPress ЮKassa для WooCommerce plugin to version 2.16.2 or later.
  • If immediate upgrade is not possible, temporarily disable the plugin or restrict access to the plugin's data files via file permissions and web server rules.
  • Limit exposure by restricting plugin API endpoints to authenticated users only, using access control or firewall rules.

Generated by OpenCVE AI on August 3, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Yoomoney
Yoomoney юkassa Для Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Yoomoney
Yoomoney юkassa Для Woocommerce

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
Title WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Yoomoney Юkassa Для Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T14:58:43.451Z

Reserved: 2026-07-22T08:52:41.029Z

Link: CVE-2026-65434

cve-icon Vulnrichment

Updated: 2026-07-27T14:58:38.573Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:08.620

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-65434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data