Impact
The Robokassa payment gateway for Woocommerce plugin suffers from an unauthenticated broken required to be logged in to reach administrative pages that manage payment settings and transaction data. This enables attackers to view or modify any functionality exposed by the plugin, potentially compromising the confidentiality, integrity, and availability of the Robokassa payment gateway for WooCommerce plugin, versions 1.8.9 and earlier. Any WordPress site that has installed a version of the plugin equal to or lower than 1.8.9 is at risk.
Affected Systems
The vulnerability affects the Robokassa payment gateway for Woocommerce plugin for all WordPress sites that have installed version 1.8.9 or earlier. The affected vendor is robokassa, and the product is the Robokassa payment gateway for Woocommerce plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high risk level. EPSS data is unavailable, and the vulnerability can be exploited remotely by sending a web request to the plugin’s administrative endpoints without any authentication, implying a remote attack vector that does not require prior access to the site’s backend.
OpenCVE Enrichment