Impact
The Robokassa payment gateway plugin for WooCommerce versions earlier than 1.8.9 fails to validate the authenticity of incoming payment notifications when the non‑default deferred‑payment option is active. An attacker can forge a notification and cause WooCommerce orders to be marked as paid or on‑hold without a real payment or a valid signature. This flaw allows an unauthenticated attacker to manipulate order status and potentially profit from fraudulent orders, thereby violating the integrity of the e‑commerce transaction process.
Affected Systems
WordPress sites that use the Robokassa payment gateway for WooCommerce plugin version less than 1.8.9 are affected. The vulnerability specifically applies to installations that have enabled the plugin’s deferred‑payment feature, which deviates from the default configuration.
Risk and Exploitability
The CVSS score of 3.7 indicates moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. However, the attack vector is likely remote, as anyone can send a forged notification to the site’s callback endpoint. The required condition is that the deferred‑payment feature is active, and no other authentication or signature checks are performed.
OpenCVE Enrichment