The Robokassa payment gateway for Woocommerce WordPress...
Low severity
Unreviewed
Published
Sep 17, 2026
to the GitHub Advisory Database
•
Updated Sep 17, 2026
Description
Published by the National Vulnerability Database
Sep 17, 2026
Published to the GitHub Advisory Database
Sep 17, 2026
Last updated
Sep 17, 2026
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.
References