Description
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation via unauthenticated access to plugin administration
Action: Apply Patch
AI Analysis

Impact

The Robokassa payment gateway for Woocommerce plugin suffers from an unauthenticated broken required to be logged in to reach administrative pages that manage payment settings and transaction data. This enables attackers to view or modify any functionality exposed by the plugin, potentially compromising the confidentiality, integrity, and availability of the Robokassa payment gateway for WooCommerce plugin, versions 1.8.9 and earlier. Any WordPress site that has installed a version of the plugin equal to or lower than 1.8.9 is at risk.

Affected Systems

The vulnerability affects the Robokassa payment gateway for Woocommerce plugin for all WordPress sites that have installed version 1.8.9 or earlier. The affected vendor is robokassa, and the product is the Robokassa payment gateway for Woocommerce plugin.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate to high risk level. EPSS data is unavailable, and the vulnerability can be exploited remotely by sending a web request to the plugin’s administrative endpoints without any authentication, implying a remote attack vector that does not require prior access to the site’s backend.

Generated by OpenCVE AI on September 10, 2026 at 16:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Robokassa payment gateway for Woocommerce plugin to the newest available release.
  • If an upgrade is not feasible, disable the plugin entirely until a secure version is available using web server rules or authentication checks so that only authorized administrators can reach them.
  • Configure a web application firewall or server access rules to block unauthenticated requests to the plugin’s administrative URLs until the plugin is patched.

Generated by OpenCVE AI on September 10, 2026 at 16:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Robokassa
Robokassa payment Gateway For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Robokassa
Robokassa payment Gateway For Woocommerce
Wordpress
Wordpress wordpress

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
Title WordPress Robokassa payment gateway for Woocommerce plugin <= 1.8.9 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Robokassa Payment Gateway For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-10T15:07:54.276Z

Reserved: 2026-08-24T17:28:20.061Z

Link: CVE-2026-78536

cve-icon Vulnrichment

Updated: 2026-09-10T15:07:48.532Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T15:17:41.030

Modified: 2026-09-10T16:17:56.440

Link: CVE-2026-78536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:00:08Z

Weaknesses