Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 | |
| Metrics |
ssvc
|
Thu, 17 Sep 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature. | |
| Title | Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT Callback | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-17T12:09:25.063Z
Reserved: 2026-09-14T16:40:14.381Z
Link: CVE-2026-91017
Updated: 2026-09-17T12:07:43.664Z
Status : Received
Published: 2026-09-17T07:16:28.773
Modified: 2026-09-17T13:17:00.147
Link: CVE-2026-91017
No data.
OpenCVE Enrichment
No data.