Description
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 17 Sep 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature. | |
| Title | Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT Callback | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-17T07:05:48.965Z
Reserved: 2026-09-14T16:40:14.381Z
Link: CVE-2026-91017
No data.
Status : Received
Published: 2026-09-17T07:16:28.773
Modified: 2026-09-17T07:16:28.773
Link: CVE-2026-91017
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.