Impact
The vulnerability in the WordPress ЮKassa для WooCommerce plugin allows the exposure of subscriber sensitive data due to improper handling of user information. This flaw means confidential subscriber details could be read by an attacker, compromising privacy and potentially facilitating further fraud or phishing attempts. The weakness is categorized as CWE‑201 (Sensitive Data Exposure).
Affected Systems
The affected vendor is Yoomoney, whose YuKassa plugin for WooCommerce is deployed on WordPress sites. Versions 2.16.1 and earlier are vulnerable. Sites running those releases or any plugin copy with the same code paths are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows a low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the most likely attack vector involves an unauthenticated or minimally privileged attacker exploiting exposed plugin endpoints or configuration files to read subscriber information. Successful exploitation would grant access to sensitive user data, potentially leading to privacy breaches or financial loss.
OpenCVE Enrichment